keybase / keybase/keybase-issues

Replacing PGP key, which I still have

Open
#2,021 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
No language data
Stars
899
Forks
40
PR merge metrics
No merged PRs in 30d

Description

[ This looks like it might require stage0 usage to resolve, which is fine, just leaves me with less-usable keybase until that stops being staging-only ]

My keybase.io account is set up using my old work PGP key. I still have access to the key, although I have pushed a revocation certificate to the public keyservers. I don't want to have multiple concurrent keys, I just want to swap which key is used, without losing all trust and proofs. Advice sought, please.

I have a new laptop key (ECC).
I have a master PGP key, which lives on a secure box where keybase won't be installed, and which cross-signs both the old work key (pre-revocation) and the new laptop key. I have also signed the new laptop key with the old work key (post-revocation). So there's a couple of options for forming the trust chain.

Signing into keybase on the laptop, choosing option 3 to use my keybase passphrase, fails because the PGP key visible on this box is not the one in my keybase account.

Are there sane ways to swap out the key?
If not yet, do the changes currently in stage0 address this scenario?

Thanks.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reviewing the stage0 changes mentioned in the issue and determine whether they address replacing an existing PGP key. Done means establishing whether the old key, new laptop key, trust chain, and proofs can be swapped without losing account continuity, then documenting the supported path or the missing capability.

Written by the indexing model from the issue text.

Assessment

Domain
cryptography, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.