keybase / keybase/keybase-issues

Document migration from SHA1 for existing keys

Open
#4,094 2 comments 0 reactions 0 assignees View on GitHub
Dominant language
No language data
Stars
899
Forks
40
PR merge metrics
No merged PRs in 30d

Description

I encounter the error

```
▶ ERROR key generation error: no valid primary key self-signature or key(s) have expired (Signature failure in packet 1: rejecting insecure hash SHA1 (98a50086f826a705)) (error 905)
```

when attempting to upload my public key to Keybase. This prevents me from using Keybase at all.

I see that there is a workaround at https://github.com/keybase/client/issues/22458#issuecomment-584179988 with the strong disclaimer

> I have a limited knowledge of what might break if you do this and other people already have your public key. Also if my real keys where at stake here, I would backup my secret keys beforehand.

As such, I do not feel comfortable following the procedure. Could you (the Keybase maintainers) please publish an officially endorsed and verified-safe procedure for working around this error?

Contributor guide

No contributing guide indexed for this repository

Research direction

The issue names no repository files or tests; begin by reviewing the linked workaround and the reported SHA1 key-generation error. Done means publishing an officially endorsed, verified-safe procedure for migrating existing keys, including guidance that addresses backups and keys already shared.

Written by the indexing model from the issue text.

Assessment

Domain
cryptography, security
Issue type
Documentation
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.