3 ms·
Yes, if a key is or might be compromised it is a good idea to rotate it. Though, since you mention you're novice, you might not be aware that in the case of Ope
by giomasce 5y ago
Yes, if a key is or might be compromised it is a good idea to rotate it. Though, since you mention you're novice, you might not be aware that in the case of OpenPGP that doesn't necessarily mean to revoke the primary key, if you set up things properly in the first place.
In OpenPGP the thing you call a "key" is actually many keys: there is a primary one and whatever number of subkeys. Subkeys are those that are actually used in day-to-day encryption and signing activity, and that you need on your computer. Primary keys are used to sign subkeys and other people's keys, but you don't need them for day-to-day activities, so you can keep them in a separate storage that is not normally attached to your computer.
If your computer gets compromised you have to revoke subkeys, but you can keep the primary key (unless you attached the cold storage to your computer while it was compromised). This makes the rotation much less painful than if you have to revoke your primary key, which implies also re-establishing signatures and trust with other people.
If you search for "gpg subkeys" you will find a few tutorials.
Even more secure is to keep the primary key offline and the subkeys in a security module, like Yubikey, Gnuk or Nitrokey Start. That makes everything much more secure, and you can easily carry your keys to other computers, knowing that when you detach your security module that computer won't have access to your keys any more.