> I'm working on a school project, including Public Key Infrastrucure (PKI).
> We are instructed to get out how long the validity period of a GPG-key
> should be set in a company or other organisations the info-material we collect
> is for in.
> First I wanted to advise a unrestricted validity, but then I remembered that
> organisations or enterprises might have often changing memebers. So I'm caught
> between the devil and the deep blue sea what to advise...
With GPG you can extend the expiry date of a key (although PGP
apparently does not recognise an extended expiry date).

Otherwise, you could revoke the keys of members who leave an
organisation, either by creating revocation certificates when keys are
created or by adding a designated revoker.

Hope that helps.
