Simon Pepping wrote:
> Robert,
> 
> You recommend that the new key be made the default key. But if it is
> only meant to be used for code signing, it cannot be the default key.
> Unless this key is on a separate keyring. Right?

a keyring can contain more than one secret key. any secret key in the
ring can be default. it's up to you but one good way to set things up is
to have one, secure keyring for both new and old code signing keys. in
this case, the new one needs to be the default.

> Is it possible to move secret keys from one keyring to another?

http://www.apache.org/dev/openpgp.html#secret-key-transfer

(probably need to add a link somewhere)

- robert


---------------------------------------------------------------------
To unsubscribe, e-mail: community-unsubscr...@apache.org
For additional commands, e-mail: community-h...@apache.org

Reply via email to