Skip to content

Keeping track of my GPG keys? #22352

Answered by mpboom
applejag asked this question in New to GitHub
Discussion options

You must be logged in to vote

First of all, I am wondering why you are deleting your keys instead of securely destroying them? I always believed that the commits that are signed with a key that is not added to your account will show up as “unverified”.

Personally, I think it’s a good idea to just use one key and move it around on some secure device like a YubiKey for example.

But there are a lot of reasons why that wouldn’t be possible. Keeping a little spreadsheet/document with the key ID mapped to the description might be the best solution then.

Replies: 2 comments

Comment options

You must be logged in to vote
0 replies
Answer selected
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants