On 3/25/11 8:00 PM, Mike Frysinger wrote:
> i wasnt aware you could extend the expiration date of a key.  that
> sort of defeats the purpose of having an expiration date doesnt it ?
> then someone could steal your expired key, extend the date, and keep
> using it.

I think that's one more reason for revocation certificates.

By the way, an expiration date that can be extended is still useful. It
can serve as a dead-man switch in case you lose the private key, see
<https://we.riseup.net/riseuplabs+paow/openpgp-best-practices#set-an-expiration-date-if-you-do-not-have-one>.

In other words, an expiration date that can be extended is still safer
than no expiration date at all, and is almost as convenient (transition
to a new key generally is somewhat inconvenient).

Attachment: signature.asc
Description: OpenPGP digital signature

Reply via email to