keybase / keybase/keybase-issues

Expired Key detection on Keybase.io

Open
#1,359 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
No language data
Stars
899
Forks
40
PR merge metrics
No merged PRs in 30d

Description

~~Quick~~ Question about users who choose to opt-out of uploading their private keys.

For the same reasons I choose not to allow my private key out of my posession, I choose to set a 1yr expiration for email encryption keys. Since joining, I wondered what would occur on keybase.io once my key did expire.

In GPGTools the keys went grey and I went on to generate new keys for my email addresses. I understand that there is a Replace Key option but my question is, what would the correct or best practices for managing the key on keybase.io.

I would think that the site would notify me that the key it is hosting has expired and dis-allow the distribution of the expired key. I understand that Sign/Verify in my case are never available due to the lack of private key hosted on your servers, but in the event someone did upload their private key, I would also expect those to be disabled until a new key is uploaded/generated.

In addition to wanting to know how the expiration management will progress (I assume it won't be left un-monitored, as it appears now), I would like to know these best practices or steps I should take in this (for me) yearly transition.

My assumption is, I should choose to Replace my Public Key then go service-to-service and use the option to Replace Proof for each.

I'll hold off a few days and see if anyone has different steps or advice.

thanks,
andrej

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by reviewing the key expiration behavior on keybase.io and the Replace Key and Replace Proof flows named in the issue. Clarify whether the expected outcome is user guidance, expiration notification, or disabling distribution of expired keys; done requires a decided behavior and documented steps or an implementation plan.

Written by the indexing model from the issue text.

Assessment

Domain
security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.