Mailing List Archive

Behaviour of sub keys
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hi Folks

I have a question regarding the behaviour of sub keys.
If I have a time limited primary subkey, and generate a new subkey. without
revoking the old one....what happens?

Are both keys used..or.is the original used until it expires with the new
one taking over?

Regards

Brian

- ------------------------------------------------------------
Brian Galbraith

Sign Only Key 0x6A6DFEFB
http://picard.uni-paderborn.de:11371/pks/lookup?op=get&search=0x6A6DFEFB
Default Encryption Key 0x63EBA765 (DH/DSA)
http://picard.uni-paderborn.de:11371/pks/lookup?op=get&search=0x63EBA765

- -----------------------------------------------------------
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.1e (GNU/Linux)
Comment: Digital Signatures Verify Author and Unaltered Content

iD8DBQE5ALFT1MQNj2pt/vsRAubqAJ4wx8DBMf/Qba9UUbxEzeAUpEa7iACdEX4g
E1b1myVGE2NFGGQXT7rnynk=
=Rdvz
-----END PGP SIGNATURE-----
Re: Behaviour of sub keys [ In reply to ]
I am tired of receiving dozens of messages of this list.

I tried many times to unsubscribe. The mailing system does not work
properly
and the owner of the list (Lord of the Lists <listmaster@gnupg.org>)
explains
me that I am not subscribed. It appears now to me as harassment.

If everybody from the list reads this message he will probably
understand his
mistake and maybe do his duty.

Brian Galbraith wrote:

> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
>
> Hi Folks
>
> I have a question regarding the behaviour of sub keys.
> If I have a time limited primary subkey, and generate a new subkey. without
> revoking the old one....what happens?
>
> Are both keys used..or.is the original used until it expires with the new
> one taking over?
>
> Regards
>
> Brian
>
> - ------------------------------------------------------------
> Brian Galbraith
>
> Sign Only Key 0x6A6DFEFB
> http://picard.uni-paderborn.de:11371/pks/lookup?op=get&search=0x6A6DFEFB
> Default Encryption Key 0x63EBA765 (DH/DSA)
> http://picard.uni-paderborn.de:11371/pks/lookup?op=get&search=0x63EBA765
>
> - -----------------------------------------------------------
> -----BEGIN PGP SIGNATURE-----
> Version: GnuPG v1.0.1e (GNU/Linux)
> Comment: Digital Signatures Verify Author and Unaltered Content
>
> iD8DBQE5ALFT1MQNj2pt/vsRAubqAJ4wx8DBMf/Qba9UUbxEzeAUpEa7iACdEX4g
> E1b1myVGE2NFGGQXT7rnynk=
> =Rdvz
> -----END PGP SIGNATURE-----

--
-'-'-'-'-'-'-'-'-'-'-'-'-'-'-'-'-'-'-'-'-'-'-'-'-'-'-'-'-'-'-'-'-'-'-'-'-'-'-'-'-'-'-'-'-'-'-'-'-'-'-

Pierre - Henri S E N E S I
http://www.senesi.org
Formateur Techno / Technology trainer
I.U.F.M. de Nice : Institut Universitaire de Formation des Maitres
University Institute for Teacher Training, Nice, France
Post. : I.U.F.M. Technology Dept. 43, Av. St. LiƩgeard F 06100 NICE
Tel. & Fax : (33) or (0) 492.07.74.89 / 80 492.09.11.02
-'-'-'-'-'-'-'-'-'-'-'-'-'-'-'-'-'-'-'-'-'-'-'-'-'-'-'-'-'-'-'-'-'-'-'-'-'-'-'-'-'-'-'-'-'-'-'-'-'-'-
Re: Behaviour of sub keys [ In reply to ]
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

> Okay, let me first preface this with: "I have not used subkeys in GnuPG".

same with me

> But the way it works currently in PGP is this:
> ...
> If there are two that are valid for that date, the first one is used by
> default. I believe that you can specify that the second one be used.
> --Len.

wrong, the newest one is used not the first (i tested it with PGP 6.5.3)
and no way to specify which subkey to use

== <EOF> ==
Disastry http://i.am/disastry/
http://disastry.dhs.org/pgp.htm <-- PGP half-Plugin for Netscape
http://disastry.dhs.org/pegwit <-- Pegwit - simple alternative for PGP
-----BEGIN PGP SIGNATURE-----
Version: Netscape PGP half-Plugin 0.14 by Disastry / PGPsdk v1.7.1

iQA/AwUBOQgPaDBaTVEuJQxkEQKH0wCdEPE0+6zQEZ8t/K6mC3v9JoRbzm0AmQEG
VuWWj+9lgHU2HAP5Y8rd0sg6
=wg69
-----END PGP SIGNATURE-----
Re: Behaviour of sub keys [ In reply to ]
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Thu, 27 Apr 2000, Disastry wrote:

>
> wrong, the newest one is used not the first (i tested it with PGP 6.5.3)
> and no way to specify which subkey to use
>
I generated new sub keys using PGP I am afraid.

I first changed te expiration date of the permanent subkey using GnuPG. I
then imported this key into PGP and then generated new subkeys with no time
overlap. That way each key is used in order.

Probably goes against a standard somewhere ;-) , but it would be nice if
that flexibility could be introduced into GnuPG.

Regards

Brian
- --
- -------------------------------------------------------
Brian Galbraith
Default Key 0x63EBA765 (DH/DSA)
http://picard.uni-paderborn.de:11371/pks/lookup?op=get&search=0x63EBA765
- -------------------------------------------------------


-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.1c-SuSE (GNU/Linux)
Comment: Digital Signatures Verify Author and Unaltered Content

iD8DBQE5CDh8EPpEmWPrp2URAncaAKDZcTPXRNb7DMVhWJhzh7bEvRMeYACgw2PK
uUatiJJdeaKJxCRtbuhGEjk=
=JEdC
-----END PGP SIGNATURE-----