keybase / keybase/keybase-issues

Revoked a PGP key, is there any way to get a revocation certificate now?

Open
#2,963 5 comments 1 reaction 0 assignees View on GitHub
Dominant language
No language data
Stars
899
Forks
40
PR merge metrics
No merged PRs in 30d

Description

I signed up for Keybase some time ago, and at the time of registration Keybase created and hosted a PGP keypair. I never really exported or used that key for anything. Fast-forward about three years. I created a new PGP keypair locally with the intent to actually start using the new keys in earnest. I revoked the old Keybase-generated key via the web UI and replaced it with my new key. All is well.

However, I now realize that my old Keybase-generated public key ended up on pgp.mit.edu and the rest of the SKS network, and I don't have any way to revoke it because I never thought to export the old private key that Keybase created.

At this point, do I have any recourse? Mainly I'm looking for a revocation certificate that I can submit to keyservers to get the old key invalidated. Failing that, is there any way to export a copy of the first private key now that it's been removed and replaced?

I have a feeling I won't like the answer. But it couldn't hurt to ask.

Contributor guide

No contributing guide indexed for this repository

Research direction

No files or tests are named. Start by reviewing the described Keybase web-UI flow and how the original PGP key was created, stored, revoked, and replaced; done would require determining whether a revocation certificate or private-key export is possible and documenting the answer.

Written by the indexing model from the issue text.

Assessment

Domain
cryptography, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
15/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.