controlling the use of subkeys

Robert J. Hansen rjh at sixdemonbag.org
Sun Dec 24 02:50:42 CET 2006


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Mike Frysinger wrote:
> sep keys means different uid's whereas a subkey is bound to the same
>  uid ...

This is not the case.  The only (required) binding between a subkey and
a UID comes from the fact that each UID has a self-signature.  If you
create a new subkey, there's no explicit binding between that and a UID.

> subkeys can have expiration limits placed on them as well, so i dont
> see how your thoughts here are specific to saying "subkeys are the
> wrong way of doing things" ... what'd i miss ?

I hate to sound like an arrogant son-of-a-so-and-so, but it sounds like
you're attempting to do complex things with OpenPGP without
understanding OpenPGP very well.

My suggestion: figure out exactly what you need it to do and send it on
to the list.  If you need more than one sentence to do it, you may not
understand your basic problem very well.

For instance: "End-users need assurance that the package is really part
of Gentoo."

Or, "I need some way to separate my Gentoo maintainer identity from my
personal identity."

Or... etc., etc.

Come up with a single sentence describing your problem, and you'll get a
ton of responses by people with ideas for how to solve it.  After a
while, you'll see some consensus emerge about which ideas have merit and
which are the products of overactive imaginations.  (This being the
internet, there may be a lot more of the latter than the former.)

Then choose the simplest, most clearly-explained idea which has merit.


-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (Darwin)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iQEcBAEBCAAGBQJFjdzyAAoJELcA9IL+r4EJoAIH/1wNVowvrWaLn2JgHm9Svl40
HpFqCvwDPpKsDpqLY0S1zYnqxcVnHHB3vpAFFPx5/IxGDi+HXa4TuqSn2DeScwb1
g0yaZ77aGtfoAQ+6yoDUOtBFRGEs6SZsnbod2yMJeGyFmW+BavBNMMvdo30JFVY0
/4XtaoIuTbdPm2/Y13xRzpt/mfw/f2I2PP84tiSNjjp+ef20O+LwpSzAC08Sa5Wc
aeeLNXHyst9hW/ya0WkaoTL1TLUpHGpH0YIsCCEtRidwWjIzw/n6QwJKvDt4Y15j
DbGfSUXb8SWph+sldlGyd7dNriRhkjLc7ZksyUwUxh6aJumMJYASSYzDPI+82VU=
=0dBt
-----END PGP SIGNATURE-----



More information about the Gnupg-users mailing list