Thanks for the answers about sub-keys
Questions I would like to find in a sub-keys FAQ. I miss the
answers
(
If any of my question is nonsense, please tell me so and, of course,
ad your own questions.
IMPORTANT NOTE: all questions have implicit: "without any known and
non trivial lost of security ?"
Questions:
(a) sub-keys are created in pars (private43;public) or just one key at
a time.
(b) can any sub-key be used to encrypt AND to sign documents?
(c) Can sub-keys share the same password / phrase with the main key
and other sub-keys ?
(d) If I have a valid (main) public + private encrypted key +
appropriate password can I generate any number of sub-keys with any
time limit and anytime I want?
(e) Someone with 2 different of my (public?) sub-keys and its
fingerprints has a good change of find out the are sub-keys of the
same key?
(f) Can I use a expired sub-key (knowing the encrypted sub-key and
the password) to decrypt or check the signature of a document -
probably encrypted or signed long ago when when the key was valid ?
(g) If some one signs my main key is it necessary to signed any sub-
key (more: and if the sub-key was created after the signature?) .
(h) Can I create a revocation certificate for a sub-key if I lost
the sub-key (but still have everything about the main key).
Sincerely Yours
Jose Simoes
.