Re: Is there a way to browse the GPG web of trust?

2011-10-09 Thread Daniel Kahn Gillmor
On 10/07/2011 12:15 PM, Melvin Carvalho wrote: Thanks I may try and set up a key server in that case. Tho I did read a report that it can be more work than anticipated. Running a keyserver isn't terribly hard. But you'll need a chunk of disk space (10G at least), a decent amount of RAM (1G),

Re: Is there a way to browse the GPG web of trust?

2011-10-09 Thread Daniel Kahn Gillmor
On 10/07/2011 11:56 PM, Jerome Baum wrote: On 2011-10-07 20:55, Aaron Toponce wrote: On Fri, Oct 07, 2011 at 06:56:36PM +0200, Werner Koch wrote: Why at all does this tool use the human readable format? I don't get it. Probably because the author of sig2dot(1) doesn't know better. Why

Why revoke a key?

2011-10-09 Thread takethebus
Hi everybody, in which cases should I revoke a key in general? Let's say I have my private key on an USB stick and lose the stick somewhere in public. The key is protected by the mantra. I'm sure, nobody knows the mantra except me. Should I revoke the key or could I keep on working with a

Re: Why revoke a key?

2011-10-09 Thread Johan Wevers
On 09-10-2011 23:30, takethe...@gmx.de wrote: in which cases should I revoke a key in general? If you think it may be compromised. Let's say I have my private key on an USB stick and lose the stick somewhere in public. The key is protected by the mantra. I'm sure, nobody knows the

Re: Why revoke a key?

2011-10-09 Thread Robert J. Hansen
On 10/9/11 5:30 PM, takethe...@gmx.de wrote: in which cases should I revoke a key in general? Whenever you feel the private key has been compromised. Unfortunately, that just switches the question to when should I consider a key compromised? Let's say I have my private key on an USB stick

Re: Why revoke a key?

2011-10-09 Thread David Manouchehri
That's really up to you, how much you value security or not. It depends on many factors, like what the key was used for; ie, if this was the Ubuntu software PGP key, you should revoke it as others are depending on it to be secure. If you used it for just signing a few files here and there, it's