rotating encryption sub keys

Joseph Oreste Bruni jbruni at me.com
Fri Aug 28 00:03:53 CEST 2009


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Would it be considered a best practice to rotate encryption subkeys on  
an annual basis, or would that be considered overkill for most uses?

I realize that messages are encrypted using ephemeral session keys  
which in turn are encrypted with public keys. Considering the small  
amount of data (i.e. sessions keys) being encrypted using public keys,  
are ciphertext attacks really even feasible?


-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (Darwin)

iQEcBAEBCAAGBQJKlwLJAAoJEFGV1jrNVRjHpJUIAJ6Cv9cFXkNmSiXFjbxKlWjJ
TylQ+LDtLCwaauHVTO+hP7V557UoP5eGuB3KyD1G5Cp+4Ec3yD/vUhh8XkidEgqH
jSRQpvabpAvQL96i4IBvxMXG8s+uKtLfxf7NMNYeqSte/q7+kK+r1VGmunb0ukLO
+m+lRus94784NHx+ivcb21gmtozLEzvZi/Y3kOu8ZK/lAnUHYFsqK6H0hFYiXcEw
I1+Wk7iggDFcuS0GcWldlbiq70W+8477mlgyKAq1bTzEzZuOEf/vgXcr+/iQtk++
hZZlvBhYcsme0NFYWBXI/hrkvAfq3pJp0wcnNf+BaTYtFBemHcd4IecvWj8KC4w=
=9z+z
-----END PGP SIGNATURE-----



More information about the Gnupg-users mailing list