D&C GLug - Home Page

[ Date Index ] [ Thread Index ] [ <= Previous by date / thread ] [ Next by date / thread => ]

Re: [LUG] PGP / GPG subkeys and IDs

 

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

debian@xxxxxxxxx wrote:
| I currently use GPG but currently have two keys

So do I, it's useful sometimes. There's no need to worry about having
two keys as long as you maintain both.

Check out mine: 0xA897FD02 and 0x28BCB3E3

|(on two seperate
| email addresses). In reading up on this, I discover - Have two keys
| keys is crazy

Not true.

| (if nothing else signing emails is already driving me
| crazy) - The current sha1 (?) hash has been broken

Only theoretically and not in a way that is worth concern.

| and therefore
| should be upgraded.

It will be replaced in due course but it's not as simple as just adding
a subkey. SHA is used in other parts of the key process that are not
simple to change and cannot be changed by the user. See the GnuPG-users
mailing list archive (via GMane or google) - it was discussed there some
months back. It's quite old news.

| So therefore I should: - Added an ID to my master key (email address
| henry.bremridge@xxxxxxxxx and hb@xxxxxxxxxxxxxxxx)

Only if you want to be able to sign emails sent From: either address
using either key.

Just decide which key you want to use, that one should have the email
address you want to use for the lug. The other one can be, as with me,
for a laptop or backup or just a key you don't use that often but which
is still maintained. Keep your revocation certificates safe and that's it.

| - Add a DSA subkey
| to sign emails

?? No need. Check your current key, it's probably Elgamal/DSA already.
That's the default on generating a GnuPG key.

| - Add a seperate Elgagal subkey to process encrypted
| emails. (There was an option to use RSA but this is apparently only
| for US use?)
|
| Could someone please confirm if my understanding is right, as if so I
|  will be changing my details with the LUG so I can use PGP.

No need. You won't be changing the keyid and that's all that matters for
the site. It'll be refreshed when someone downloads the group keyring.

- --

Neil Williams
=============
http://www.codehelp.co.uk/
http://www.dclug.org.uk/
http://www.isbn.org.uk/
http://sourceforge.net/projects/isbnsearch/

http://www.biglumber.com/x/web?qs=0x8801094A28BCB3E3
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.0 (Darwin)
Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org

iD8DBQFCozCDk7DVr6iX/QIRAi/yAKCC2UJcRVNmG6HTFlci3opgjtb81ACfV8pL
py4oadrahAlq47TYUy65hKg=
=qZrM
-----END PGP SIGNATURE-----

--
The Mailing List for the Devon & Cornwall LUG
Mail majordomo@xxxxxxxxxxxxx with "unsubscribe list" in the
message body to unsubscribe. FAQ: www.dcglug.org.uk/linux_adm/list-faq.html