Strategies for offline PGP key storage
Strategies for offline PGP key storage
Posted Oct 5, 2017 12:53 UTC (Thu) by anarcat (subscriber, #66354)In reply to: Strategies for offline PGP key storage by merge
Parent article: Strategies for offline PGP key storage
1. gpg chooses the latest signing subkey (I would have expected it would sign with all available signing subkeys)
2. notmuch-emacs and mutt do not allow you to choose which subkey to use to sign outgoing messages
3. debsign *does* allow you to choose the signing subkey, but that's about the only thing
I had to go back to inline signing to send email... And I had to specify the signing key with a bang ("!") at the end, which was weird and unusual (I would have expected the keygrip to work here for example).
So in short, it's a pain in the back to rotate signing keys, I wouldn't recommend having a workflow based on doing that on a regular basis, unless you control key propagation.
