Yet again, it has come time to rotate my PGP/GnuPG private key. My old key (1ED5E5A301C3D109904022893C7775DD37811E62) actually expired a couple of weeks ago, and I've been procrastinating writing up this transition.
The new key is 0xC6496DEB3DA8E9B5
(full fingerprint: 24F8AA354990F3F562EC014BC6496DEB3DA8E9B5)
You can also find it at https://files.roguelazer.com/roguelazer.gpg.
It has also been attached to my keybase.io account1 and my Github profile.
It is cross-signed by the old key.
My signed transition document is below, and can also be found at 2022-05-28-key-transition-statement.txt.asc if you prefer to download it directly.
As far as I know, I never received a single mail or message encrypted to my previous GPG key, and really only used it for signing some git tags. It may be that this will be the last GPG key I generate. Everything at work that used GPG has moved to age and/or minisign.
Transition Statement
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256My name is James Matthew Brown. This document serves as notice that I am transitioning from PGP/GPG key 1ED5E5A301C3D109904022893C7775DD37811E62 to PGP/GPG key 24F8AA354990F3F562EC014BC6496DEB3DA8E9B5.
You can fetch the new key using GnuPG with
gpg --keyserver hkps://keys.openpgp.org --recv-key 24F8AA354990F3F562EC014BC6496DEB3DA8E9B5
If you already trust my existing key, you can validate the new one with
gpg --check-sigs 24F8AA354990F3F562EC014BC6496DEB3DA8E9B5
Sorry for doing this so late this year. -----BEGIN PGP SIGNATURE-----
iQIzBAEBCAAdFiEEHtXlowHD0QmQQCKJPHd13TeBHmIFAmKSY2AACgkQPHd13TeB HmKzHA//Vp6r8yE0nYkil8MqMJxbD7l6xMJOF5/A4NvR7XFuC1alKTisLB0jcKFa /gUNeXZ0m9hAbpvbjPDPYdraqUCb4fpk/n7szdA8XKJTWL09zSc1OKP+g5vAv/jd 6hbE6l44BJsjdg8JpL+M4YUuWcPoeBdZDETweWsUaseSH0I33jWKzma36HrCFnAL bvk1hvU5AV1muRND9w1KfKCa0Akg3ySyKlkQx9HN/EIAnrN6FMTcBOpfchdmbqH4 JhER5vnajcbz5MTw3B4skAgIFB9U+bn93ieVqrWzTxYBaPE7OQMNBQsaB6K3AffZ ZIgjPja/bWDIhqFb7KnH1hOfDk4o6tnSfvalanXjJK2xFtGkjDKOGdQJh58LfiOp qzzmYF6asaTnpCm2OykUmfdPPZWdKPdsz68tT3rMm9q3nhpkWgMCji82bl1uV95I dHrB2RaSgpnxfXWrmPkSjEyErkDeGSnA7Sz4+Bknzgk7tLMSzhtFFdZAv7XLxZOu 2IImv5D/TxHTApeTuEniGUCIucZeCWj3Dz9b+ChR5QxWJa1snjlwMpr5ybGl+4p1 eMGi8D0k0zG8fbzLmpUeKKhllgs5L2ZSJGMa+jdnaSEkvuPwJrAzwyDy53jWTssf lWjK9SDjdRptoiCZkv8ZXDNUG2NOd/ZOgzSrnOsa3EIMxyAdu7aJAjMEAQEIAB0W IQQk+Ko1SZDz9WLsAUvGSW3rPajptQUCYpJjYAAKCRDGSW3rPajptYRNEAC3Ak2V VtNEfUFoijEaaTuXgMXwhzMnVjQOhF2U2or0a2iop+OtdAx75tzUelQgG/zlXOO6 3oQj1Ye5xzbmqcI9fWtyqAyv2YXXm6bTCGZHIWUYcdql10ompDNW5Us0DllN7vai iuWoe+1qC5ZYY37lSJYL2UeIbX0MKbWqbsX8Nabr5AiM2MRBjDVy3x++UYRUmYbZ XITN4drDRv5Sst724PbTcw3Hpw3h6aSGMmfeOh0adjE1m01XCxYJ+UhHXf8w7ncV 960PD7Jmh2rGZIA5nGqWcJ5+AAufgVCdlLvdwGcRT35qTnPWHZdZhz76/Iy0hvoK pHEk35G1DpDX3GiE+EXNyxZyefpAw9+E5sU+6rnBxJdr0leQ+PiZrBSGXO81gC+b xsNOgWm67iUU69FhpCWcBKg7qVLJWKJyHeFkytgFiagGqSOB12LKojUYAXBIDdOr Lpod/6QUCZLwBXvK/rDhAQbuSBeWz2whIthA2hShvfNR+TUPZwhdxFG313AnI7tH 6uJlxqp56vSCjCsmTlzB5oV2h3nMzKF4OcWv4tmgEDdFW2p23AnexkBrO1hNa3IM pCgQuAVhoBoxP+37L1Wd5JQ8kg8qpaamTT0DH7XnvsEvuT0PYOmEXMZKCf5vAtu8 0SDN/ey/Bs9eASL6/ZPCjDeTsuGyshFSpnrPGg== =GaG4 -----END PGP SIGNATURE-----
For whatever this is worth; it seems like Keybase is totally dead since they were acquired, and I expect them to shut down any minute.
Want to comment on this? How about we talk on Mastodon instead? Share on Mastodon