6 Jun 2021
@ravenclaw900:matrix.orgravenclaw900 * I think that they only need to have the master public key, as they are subkey pairs, as in part of the main key. 11:59:03
In reply to @ravenclaw900:matrix.org
I think that they only need to have the master public key, as they are subkey pairs, as in part of the main key.
Oh ok. I think things are starting to fall into their places in my mind. Thnx
@finlaydag33k:finlaydag33k.nlAroop Roelofs

No, cryptographically speaking they only really need to know the keys that are actually used.
I can send someone the public part of my signing key (but none of the others) and sign to my hearts content just fine.

However, a subkey on its own is not to be trusted.
So you tend to send them as a "bundle" most of the time.
This bundle contains all public keys (you can ommit the public keys that won't be used for your action tho if so desired).
Your certification key (it's public part ofc) is the important one as that is basically you.
If they trust your certification key and your encryption key is certified with said certification key, then know they can trust your encryption key (as long as the certificate is valid, of course).

You should protect the private key of your certification key at all cost (ofc, protect all of them).
If they hack any of the other keys, they only can use that part to do as they please.
However, if they have the private key of your certification key, they can create new subkeys at their own leasure.

Subkeys are just more localized webs of trust.

@aitvaras:evilwoods.netaitvarasThank you for the explanation. It's clearer now.16:30:06
7 Jun 2021
So I have been reading about gpg and I think I get it that the master key pair

Due to somewhat offensive nature we call it a "primary key pair"... (just kidding "primary" is in the spec, "master" is just a new term invented later).

8 Jun 2021
@blue_penquin:fairydust.spaceblue_penquinThis is a day late but PGP is 30 years old this year :O https://philzimmermann.com/EN/essays/PGP_30th/06:28:21
12 Jun 2021
17 Jun 2021
19 Jun 2021
23 Jun 2021
@cassepipe:matrix.orgcassepipeSo i am playing around with the sq from sequoia-pgp and having fun. It works but there's something odd16:39:31
@cassepipe:matrix.orgcassepipeI am actually able to encrypt using a private key16:40:27
@cassepipe:matrix.orgcassepipeAnd when I try to decrypt with the private key, it works16:40:47
@cassepipe:matrix.orgcassepipeIs it not strange ?16:40:52
@wiktor:stratum0.orgWiktor not strange as usually "private key" file contains public parts of the key too, you can play around with sq packet dump on both files cassepipe 18:26:26
26 Jun 2021
5 Jul 2021
8 Jul 2021
9 Jul 2021
10 Jul 2021
18 Jul 2021
22 Jul 2021
23 Jul 2021
