Re: Debian GPG Key maintainence?
On Mon, Jan 06, 2003 at 07:56:31PM +0000, Steve Kemp wrote:
> Recently I became a member of the Debian project, with
> a particular email address - one that I've been exclusively
> using since around 1996.
> Due to a variety of circumstances I've now stopped using
> that - although I can still read the mail delivered there.
> What's the best way to start using the new address with
> my Debian duties? Presumably I should create a new key
> and sign it with the old one.
Merely create a new User-ID with your new email-adress and sign it (and
try to get signatures from other DDs eventually) keeping your old key.
> If that's uploaded to keyservers is that sufficient, or
> do I need my keyring entry updated? Something that seems
> to take "a while".
Yes, and it will probably be rejected because there's no need to weaken
the web of trust for such an issue.
<Overfiend> My package is not called XFree86 4.2.1-CVS-HEAD
<asuffield> Overfiend: maybe you should create one. put any old crap it
in, and make it conflict with all MUAs. that way they can't file
bugs when they discover it's a red herring.