aboutsummaryrefslogtreecommitdiffstatshomepage
diff options
context:
space:
mode:
authordrduh <github@duh.to>2020-05-03 18:11:37 +0000
committerGitHub <noreply@github.com>2020-05-03 18:11:37 +0000
commita1a4a303f9c2ee45089a02d24367c9848c44bb7a (patch)
tree15f9fe368e9e52fc3daadafbbe3fa77b6bcb997f
parentMerge pull request #170 from murphy83/Abort-Trick (diff)
parentAdd instruction to create a revoke certificate (diff)
downloadYubiKey-Guide-a1a4a303f9c2ee45089a02d24367c9848c44bb7a.tar.gz
Merge pull request #177 from apiraino/revoke-cert
Add instructions to create a revoke certificate
Diffstat (limited to '')
-rw-r--r--README.md15
1 files changed, 15 insertions, 0 deletions
diff --git a/README.md b/README.md
index e8bba6e..7c0ef39 100644
--- a/README.md
+++ b/README.md
@@ -27,6 +27,7 @@ If you have a comment or suggestion, please open an [Issue](https://github.com/d
* [Authentication](#authentication)
* [Add extra emails](#add-extra-emails)
- [Verify](#verify)
+- [Create a revoke certificate](#create-a-revoke-certificate)
- [Export](#export)
- [Backup](#backup)
- [Configure Smartcard](#configure-smartcard)
@@ -858,6 +859,20 @@ $ gpg -o \path\to\dir\mastersub.gpg --armor --export-secret-keys $KEYID
$ gpg -o \path\to\dir\sub.gpg --armor --export-secret-subkeys $KEYID
```
+# Create a revoke certificate
+
+Although we will backup and store the master key in a safe place, it is best practice to never rule out the possibility of losing it or having the backup fail. Without the master key it will be impossible to renew or rotate subkeys or generate a revoke certificate, our keychain will be basically useless.
+
+Even worse, we cannot advertise this fact in any way to those that are using our keys. It is therefore safe to assume that at some point in the future this *will* happen and the only thing that will allow us to deprecate our *orphan* keys is a revoke certificate.
+
+In order to create the revoke certificate:
+
+``` console
+gpg --output revoke.asc --gen-revoke $KEYID
+```
+
+The newly created `revoke.asc` file should be stored (or printed) in a place that allows us to retrieve it in case our backup strategy fails.
+
# Backup
Once keys are moved to YubiKey, they cannot be moved again! Create an **encrypted** backup of the keyring and consider using a [paper copy](https://www.jabberwocky.com/software/paperkey/) of the keys as an additional backup measure.