ietf-openpgp
[Top] [All Lists]

Re: OpenPGP Sub Keys (Was: key flag for authentication)

2003-06-16 04:48:46


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hello Ian,

On Mon, 16 Jun 2003 09:18:09 +0100, you wrote:

Imad R. Faiad wrote:
I would like to propose that signing sub keys be disallowed 
in OpenPGP.

This would stop people keeping their master signing key on a more secure
offline machine, and using it to sign shorter-lifetime signing subkeys
which can be used on a day-to-day basis to sign messages :(

Let me add, and no offence of course, from the fact that you are
relegating those short-lifetime signing sub keys to a less secure
environment, I infer that you have no confidence in them, so how
do you expect others to trust such keys, or signatures generated
by them for that matter?  You might as well not sign at all.

my 2c

Best Regards

Imad R. Faiad

-----BEGIN PGP SIGNATURE-----
Version: 8.0.2irf
Comment: KeyID: 0xBCC31718833F1BAD
Comment: Fingerprint: 75CD 96A7 8ABB F87E  9390 5FD7 2A88 4F45

iQEVAwUBPu24HrzDFxiDPxutAQKFHQf9GdGwv8ghOX5v1vNjLQqfA+k31m1POKu9
v65xCLzscw7tkkdtlshecypvSFnAtpgx3ih/XCWkpic00wwOcqN7paqi/LNSsJLS
tju/1OTSLhL47MDJND1XK8CoGo4cv0id70y9Uo344BoR6Z7pQStLzkK7wTA9yeQb
KEWQu75H/HUnARCpmjVcjpcasqeYqEnyowra9T5xIElEC1KSyAkqE2cbN+UTvLoa
Nz3BPQb9k2ZMD6GslzpHx3yS4S2dpEmd8isu6bTksjljF9g2g4iK1W/1idM3gdAx
sBb1ZHAbjt+7kucya4aDgJnf5O6PdtaKR3o5hUF5W5jgyx4lIQuAfQ==
=AIA0
-----END PGP SIGNATURE-----