Gentoo Archives: gentoo-dev

From: "Andreas K. Huettel" <dilfridge@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] validity of manifest signing key
Date: Fri, 25 Mar 2011 19:42:47
Message-Id: 201103252042.21614.dilfridge@gentoo.org
In Reply to: Re: [gentoo-dev] validity of manifest signing key by Mike Frysinger
1 > > -) Extend expiry date and upload again?
2 >
3 > i wasnt aware you could extend the expiration date of a key. that
4 > sort of defeats the purpose of having an expiration date doesnt it ?
5 > then someone could steal your expired key, extend the date, and keep
6 > using it.
7
8 The expiration date is a property of the self-signature. If you can re-do the self-signature (i.e. you have access to the secret key), you can extend the expiration date.
9
10 If someone steals your expired key, *and* has full access to the secret part- yes, then he can reactivate it.
11
12 If you want to permanently disable your key, you should generate a revocation certificate (which is also a signature). AFAIK, there is no way to revoke a revocation.
13
14 --
15 Andreas K. Huettel
16 Gentoo Linux developer - kde, sci, arm, tex
17 dilfridge@g.o
18 http://www.akhuettel.de/

Attachments

File name MIME type
signature.asc application/pgp-signature