[ Team LiB ] |
Recipe 7.22 Revoking a Key7.22.1 ProblemYou want to inform a keyserver that a particular public key (of yours) is no longer valid. 7.22.2 Solution
7.22.3 DiscussionAt times it becomes necessary to stop using a particular key. For example:
Whatever the reason, it's time to inform others to stop using the corresponding public key to communicate with you. Otherwise, if the key is lost, you might receive encrypted messages that you can no longer decrypt. Worse, if the key has been stolen or compromised, the thief can read messages encrypted for you. To tell the world to cease using your key, distribute a revocation certificate for that key: a cryptographically secure digital object that says, "Hey, don't use this public key anymore!" Once you create the certificate, send it directly to your communication partners or to a keyserver [Recipe 7.19] for general distribution. For security reasons, the revocation certificate is digitally signed by you, or more specifically, with the private key that it revokes. This proves (cryptographically speaking) that the person who generated the certificate (you) is actually authorized to make this decision. But wait: how can you create and sign a revocation certificate if you've lost the original private key necessary for signing it? Well, you can't.[3] Instead, you should create the certificate in advance, just in case you ever lose the key. As standard practice, you should create a revocation certificate immediately each time you generate a new key. [Recipe 7.6]
Guard your revocation certificate as carefully as your private key. If a thief obtains it, he can publish it (anonymously) and immediately invalidate your keys, causing you a big headache. 7.22.4 See Alsohttp://www.keyserver.net/en/info.html and http://www.keyserver.net/en/about.html. |
[ Team LiB ] |