Gentoo Archives: gentoo-dev

From: "Paweł Hajdan
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] validity of manifest signing key
Date: Sat, 26 Mar 2011 09:37:24
Message-Id: 4D8DB3A1.4090500@gentoo.org
In Reply to: Re: [gentoo-dev] validity of manifest signing key by Mike Frysinger
1 On 3/25/11 8:00 PM, Mike Frysinger wrote:
2 > i wasnt aware you could extend the expiration date of a key. that
3 > sort of defeats the purpose of having an expiration date doesnt it ?
4 > then someone could steal your expired key, extend the date, and keep
5 > using it.
6
7 I think that's one more reason for revocation certificates.
8
9 By the way, an expiration date that can be extended is still useful. It
10 can serve as a dead-man switch in case you lose the private key, see
11 <https://we.riseup.net/riseuplabs+paow/openpgp-best-practices#set-an-expiration-date-if-you-do-not-have-one>.
12
13 In other words, an expiration date that can be extended is still safer
14 than no expiration date at all, and is almost as convenient (transition
15 to a new key generally is somewhat inconvenient).

Attachments

File name MIME type
signature.asc application/pgp-signature