Re: a bunch of questions

2017-11-10 Thread Peter Lebbing
On 10/11/17 09:50, Francesco Ariis wrote: > A general word on expiry dates: you can always modify them as you > go (that's what I do), they are not set in stone? Well, this depends on your threat model. If I can control what one of your peers sees, I could strip the self-signatures that change the

Re: a bunch of questions

2017-11-10 Thread Francesco Ariis
On Fri, Nov 10, 2017 at 12:27:22AM -0500, charlie derr wrote: > I believe that the key I'm signing this message with is 2048 bits and > will expire next year. If I've got either of those details wrong, please > correct my error(s). [...] Hello Charlie, I see no expiration date on your key (409

Re: a bunch of questions

2017-11-09 Thread Robert J. Hansen
> I believe that the key I'm signing this message with is 2048 bits and > will expire next year. If I've got either of those details wrong, please > correct my error(s). No. There's no expiration date on your certificate, and it's a 4096-bit RSA keypair. > What size key do you recommend I create