> Why is this behavior? I took a glance at RFC4880 and I could not find a > requirement that only primary keys are used for certifying, although it > is very possible that I just missed it. Does the subkey have the certify capability on it? If the subkey isn't marked for certifying, it can't be used to certify.