This explains it very well:
idea. I have some keys from the early 90's that I don't remember the passwords of, that just take up space on the keyservers, but I can't do anything with.
It seems a rather short period.
If you sign your new key with the old one, there is a web of thrust that goes back to the signers of the old key. But I don't know how that works with expired keys. There is probably less thrust when there are expired keys involved.
Whatever period you choose, at least generate revokation certificates
and keep them in a save place, so if you loose the passwords of your key you can still revoke them...
And I just read that you can always extend the expiration date on an already expired key, and send that out to the key servers. So there is
no reason to not use an expiration date on keys. I think I'm gona set
mine to 5 years...
Sysop: | altere |
---|---|
Location: | Houston, TX |
Users: | 69 |
Nodes: | 4 (0 / 4) |
Uptime: | 18:09:46 |
Calls: | 1,160 |
Files: | 8,179 |
Messages: | 300,757 |