Recommendations for handling (multiple) user IDs - personal and company ones

Doug Barton dougb at dougbarton.us
Fri Jun 7 22:22:04 CEST 2013


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

I'm not sure where you're getting this "15 years" number.

In any case, the conventional wisdom is that for completely distinct
roles (such as personal vs. work) that separate keys is the way to go.
That way when you no longer have the work role the whole key can be
retired, and there is no question down the road about
old/expired/revoked subkeys. Personally I have used this strategy and it
has worked well for me. Also, some companies have key escrow practices
that make using a separate key the only viable option.

OTOH, others on this list, and many keys that I have signed over the
years, have combined various roles (i.e., personal and work e-mail
addresses) on the same key, so that practice is not uncommon.

hope this helps,

Doug


On 06/07/2013 01:09 PM, Branko Majic wrote:
| Hello again,
|
| With my OpenPGP smart-card set-up almost done (master key on one card,
| everyday sub-keys on second), I'm thinking a bit about how I should
| handle my user ID, since the master key will be valid for 15 years.
|
| What are the general recommendations on what to use the user ID for
| (i.e. which e-mail addresses)?
|
| In addition to adding my home/personal e-mail information, I was
| thinking of maybe adding my (current) company's e-mail as well (and
| starting to actually sign my outgoing work mails with the same card).
| The catch is that I might not stay in the company for full 15 years.
|
| I've read-up a bit on how the user IDs are handled, and seen that
| keyservers will merge user IDs instead of replacing them.
|
| So, is it common that people reuse the keys in this way (for both
| personal and work communications)? Any bad experiences or
| recommendations someone could share on this topic?


-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.19 (GNU/Linux)

iQEcBAEBCAAGBQJRskDsAAoJEFzGhvEaGryE5nUH/i2awrMkNgJEq/pTB6If5Drb
q4pn/mV9QBhGH+AG5DT9wFf2j85I9gu+Fr+GXkGfQcJW6ykIFZgsSUh8kBOeym97
FZd2X3/SbO7BifTIL1GivPUlcxWKicLrYzYTFjKXfny6mhMJbyPbeJIWZ9QTUtkW
6ruuItTCnV/8TzmIzEMSq4VueLfMy+AXSEXD1OZLInXfwDSStwKYkckj7483We9z
Bkl+CE18+LZFCUMkaAMEPdoxIgkHxUD0u3tfHKIc5aSNBUJplKqwSke4+zKR/A72
MzY9Y53EogzOxNpIlg+/7xT1u9MDtNYR9fDffjJrKssTpUK/B9Dc3JW1tNTXAiE=
=dJhr
-----END PGP SIGNATURE-----



More information about the Gnupg-users mailing list