Am Sa 14.12.2013, 17:01:23 schrieb adrelanos:
> > Am Fr 13.12.2013, 22:56:07 schrieb adrelanos:
> >> Hi,
> >> 
> >> Is it possible to create a revocation certificate just for sub keys and
> >> not the master key?
> > 
> > --edit-key 0x12345678
> > key 1
> > revkey
> 
> That's doesn't create a revocation certificate, that revokes the key.

It does create a revocation certificate. But it imports it automatically. 
There is a simple solution, maybe (matter of taste) easier than dkg's 
proposal:

Make a backup of the key (i.e. export both secret and public key), do the 
above, export the certificate (public key), delete both secret and public key 
and import your backup. The exported certificate contains the revocation 
certificate.

You may reduce the file by deleting all but one UIDs and all other subkeys 
after the backup and before the revkey.


Hauke
-- 
Crypto für alle: http://www.openpgp-schulungen.de/fuer/unterstuetzer/
http://userbase.kde.org/Concepts/OpenPGP_Help_Spread
OpenPGP: 7D82 FB9F D25A 2CE4 5241 6C37 BF4B 8EEF 1A57 1DF5

Attachment: signature.asc
Description: This is a digitally signed message part.

_______________________________________________
Gnupg-users mailing list
Gnupg-users@gnupg.org
http://lists.gnupg.org/mailman/listinfo/gnupg-users

Reply via email to