Same private key on multiple sites

David Shaw
Sat Aug 18 03:18:04 2001

Also look at --export-secret-subkeys, which does almost the same thing, but blanks out the secret part of the primary signing key. This is really useful as it lets you keep the important primary key (the one that collects signatures, and thus ties you to the web of trust) offline altogether, and just use subkeys which are easily creatable and revocable to do your work. I'm a big fan of this feature, as I also need to have keys in multiple places. Hmm. Should --export-secret-subkeys do an automatic --no-comment? At least for DH keys, GnuPG generates comment packets with the key factors. Is there a security implication with this?