#59 new
rains

Show Informative message and fixing steps if subkey of a sec/pub key is about to or has expired

Reported by rains | June 16th, 2011 @ 12:46 PM

2016-02-17 updated by Steve:

With an expired subkey, users find themselves unable to encrypt and or sign mails - depending on key capabilities.

Currently

Neither GPGMail nor GPG Keychain warn the user about subkeys which have expired or are about to expire.

Expected

GPG Keychain should inform the user on every opening

  1. whenever there is any sec/pub key with an expired subkey and no unexpired subkey in the keyring
  2. and warn users, when a subkey is about to expire in the next four weeks
  3. color keys with expired subkeys and no unexpired subkeys

Show following info msg on each startup as long as the subkey is not renewed:

Attention: Your subkey for the following key has expired or is about to expire.

%&Name Primary userID KeyFingerprint

We recommend to create a new subkey. That will ensure your setup stays fully operational.

1. double-click the sec/pub key in question
2. select the subkey tab
3. click "+" to create a new subkey

Once your key is updated, don't forget to share it with your contacts. In case your public key resides on the key servers, please upload your updated key, so that the new subkey is reflected.

See also:

Notification

  • should show in OS X notification center
  • should show each time GPG Keychain is opened and the subkey has not yet been renewed
  • should also show in GPGMail

Timing

  • 4 weeks ahead: first warning
  • 2 weeks ahead: second warning
  • 1 week ahead: daily warning
  • expired: ideally this situation would be prevented by the warnings shown prior to the key expiration. But for expired keys / subkeys, weekly warnings should be shown to the user

+1 another user in live-chat running into this on 2014-08-05

Comments and changes to this ticket

Please Sign in or create a free account to add a new ticket.

With your very own profile, you can contribute to projects, track your activity, watch tickets, receive and update tickets through your email and much more.