Re: Expiration semantics (Re: draft-ietf-openpgp-rfc2440bis-06.txt)

2002-09-24

On Mon, Sep 23, 2002 at 03:50:06PM -0400, Michael Young wrote:

Certifications are statements about the ownership of a key, not its
lifetime; it should be legal to make a certification that will outlast
the key's (CURRENT) expiration time.

Legal?  Of course; the signer may have out-of-band information that a
long certification validity period is OK.  But by default, the current
key expiration time should not be exceeded.

