keybase / keybase/keybase-issues
Revoked a PGP key, is there any way to get a revocation certificate now?
- Dominant language
- No language data
- Stars
- 899
- Forks
- 40
- PR merge metrics
- No merged PRs in 30d
Description
I signed up for Keybase some time ago, and at the time of registration Keybase created and hosted a PGP keypair. I never really exported or used that key for anything. Fast-forward about three years. I created a new PGP keypair locally with the intent to actually start using the new keys in earnest. I revoked the old Keybase-generated key via the web UI and replaced it with my new key. All is well.
However, I now realize that my old Keybase-generated public key ended up on pgp.mit.edu and the rest of the SKS network, and I don't have any way to revoke it because I never thought to export the old private key that Keybase created.
At this point, do I have any recourse? Mainly I'm looking for a revocation certificate that I can submit to keyservers to get the old key invalidated. Failing that, is there any way to export a copy of the first private key now that it's been removed and replaced?
I have a feeling I won't like the answer. But it couldn't hurt to ask.
Contributor guide
No contributing guide indexed for this repository
Research direction
No files or tests are named. Start by reviewing the described Keybase web-UI flow and how the original PGP key was created, stored, revoked, and replaced; done would require determining whether a revocation certificate or private-key export is possible and documenting the answer.
Written by the indexing model from the issue text.
Assessment
- Domain
- cryptography, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 15/100