Using single subkey for both signing and encryption?

John Clizbe John at
Mon Nov 2 00:22:00 CET 2009

gpg.mexon at wrote:
> Hi, I just have a basic question about subkeys.  When I create an RSA
> subkey I only have the option to create one for signing or encryption,
> not both.  Why is that?  There's nothing different about the keys
> themselves, is there?  Is there supposed to be some increased security
> to doing it this way?

Given that the underlying mathematics is the same for encryption and signing,
only in reverse, if an attacker can convince a key holder to sign an unformatted
encrypted message using the same key then she gets the original.

