<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>[LINICKX].com &#187; pgp</title>
	<atom:link href="http://www.linickx.com/tag/pgp/feed" rel="self" type="application/rss+xml" />
	<link>http://www.linickx.com</link>
	<description>Moments of Genius followed by Trash.</description>
	<lastBuildDate>Tue, 24 Jan 2012 16:42:00 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Trying to Clean Up / Delete PGP Keys.</title>
		<link>http://www.linickx.com/391/trying-to-clean-up-delete-pgp-keys</link>
		<comments>http://www.linickx.com/391/trying-to-clean-up-delete-pgp-keys#comments</comments>
		<pubDate>Fri, 29 Feb 2008 13:14:56 +0000</pubDate>
		<dc:creator>Nick</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[pgp]]></category>

		<guid isPermaLink="false">http://www.linickx.com/archives/391/trying-to-clean-up-delete-pgp-keys</guid>
		<description><![CDATA[Here&#8217;s the story, moons ago when I started in security somebody told me all about Pretty Good Privacy (PGP) in my enthusiasm I got straight on to downloading a copy; now this was a long time ago and I can&#8217;t &#8230; <a href="http://www.linickx.com/391/trying-to-clean-up-delete-pgp-keys">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Here&#8217;s the story, moons ago when I started in security somebody told me all about <a href="http://en.wikipedia.org/wiki/Pretty_Good_Privacy">Pretty Good Privacy</a> (<a href="http://www.pgp.com">PGP</a>) in my enthusiasm I got straight on to downloading a copy; now this was a long time ago and I can&#8217;t remember if it was freeware or a trial from pgp.com, but either way I got straight onto generating a public/private key pair. </p>
<p>Since I was still on new technology enthusiasm I made sure that my private key had a <strong>very, very</strong> strong password, all happy with my success I then try to encrypt a file to myself only to find I could not open the encrypted file. After a few trys of drying to decrypt the file I give up and decide that I must have &#8220;typo&#8217;d&#8221; the password when generating the key, no matter, I simply delete the key pair and start again. For a second time I use a very, very strong password for key generation and encrypt a file, sadly the same thing happens, I just cannot decrypt the files. For the third key I use something new, still a strong password but now 10char instead of the 50 (<em>yes it was a sentence</em>) I used before.</p>
<p>All is fine until I then start sending emails to my colleagues whom inform me that there 4 keys on the web &#8211; DOH! It appears that my client at the time was set to automagically sync it&#8217;s keys with the server and has published my rubbish keys to the internet!</p>
<p>But the story of key woe doesn&#8217;t end there, by a strange course of coincidence a week before I was due to leave that company my laptop hard-drive burnt out taking my private keys with it, so now there are 4 keys on the internet (<em>with two different e-mail addresses</em>) which I cannot revoke.</p>
<p>At the time I remember finding <a href="http://pgp.mit.edu/faq.html">this faq </a>which basically says if you&#8217;ve published a public key and lost the private &#8211; Tough! As such these keys have ever since layed unused on their server, you would think that they would automatically clear down keys that clients never request&#8230;. oh well!</p>
<p>I&#8217;ve started using PGP at work again and wanted to somehow clear up the mess I created all them years ago. The &#8220;you can&#8217;t delete&#8221; still stands but I found<a href="http://www.rossde.com/PGP/pgp_keyserv.html#noremove"> this useful article</a> which explains something you can do. If you generate new key-pairs sign the old public keys, and revoke your new key you can &#8220;show to the world&#8221; that you know that key and since you&#8217;ve revoked yours it probably can&#8217;t be trusted. So that&#8217;s what I&#8217;ve tried to do, the whole PGP key managment thing is still a bit of a mine-field but, if you <a href="http://pgp.mit.edu/">search for me</a> hopefully what I&#8217;ve achieved is&#8230;</p>
<p>PGP Key <code>895C5474</code> belongs to me (<em>I just generated it</em>) I have signed my mistakes, Keys <code>165E3E9, 884FA434</code> &#038; <code>17A50106</code> and revoked <code>895C5474</code>.<br />
PGP Key <code>B9E407B7</code> also is a new one of mine, I have signed <code>825E0D45</code> and revoked <code>B9E407B7</code>.</p>
<p>The other key <code>AC4DA9FA</code> is my new work key and is still valid.</p>
<p><a href="http://www.linickx.com/gpg-key">My personal public key</a> has not been published (<em>yet</em>) but is <a href="http://www.linickx.com/files/GPG-KEY-NICK">available here</a>.</p>
<p>Fingers crossed I&#8217;ve taken enough precautions (<em>backing up keys and passwords in separate secure locations</em>) that this will never happen again, but I guess only time will tell, we all make mistakes <img src='http://www.linickx.com/wp/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<img src="http://www.linickx.com/wp/wp-content/themes/linickx_v2/images/nick_sig_bggrey.png" alt="Nick" /> <hr/>Copyright &copy; 2012 <strong><a href="http://www.linickx.com">[LINICKX].com</a></strong>. This Feed is for personal non-commercial use only. Please check my <a href="http://www.linickx.com/?page_id=63">Site Terms and Conditions</a> for full details on copyrights. If you have any concerns with the content of this feed you may <a href="http://www.linickx.com/contact">contact me here</a>.<br/><span style="float: right;font-size: 7pt"><a href="http://blog.taragana.com/index.php/archive/wordpress-plugins-provided-by-taraganacom/">WP Copyright Plugin</a></span>]]></content:encoded>
			<wfw:commentRss>http://www.linickx.com/391/trying-to-clean-up-delete-pgp-keys/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

