Guide to Renewing GPG Subkeys in 2025: Simplified Process for Key Management
By
ibobev
Warm and crisp on the edges. A bagel with a bit of bite.
Summary
The article provides a practical guide for renewing GPG (GNU Privacy Guard) signing and encryption subkeys in 2025. It explains that while the author previously wrote about this process, advancements in GPG's user-friendliness have simplified the procedure. The guide outlines steps for working with GPG keys, including using an airgapped computer for security, handling master/primary keys, and managing subkey renewals. The content serves as a technical tutorial for users who need to maintain their GPG key infrastructure.
Key quotes
· 4 pulledIt is that time of year again when my gpg signing and encryption subkeys expire.
I wrote about how to renew them before, but it was a long time ago and the process has gotten simpler thanks to advancements in gpg user friendliness.
Hypothetically, I sit down at a blank, airgapped computer that is only used for this process, into which I insert whatever media holds the secret master key.
I think the formal terminology these days is to call the master key a primary key.
You might also wanna read
Suspicious hidden message discovered in jqwik testing library 1.10.0
A developer reports discovering a suspicious string in the jqwik testing library (version 1.10.0) that appears during Maven test runs. The s
Anthropic Releases Free Security Plugin for Claude Code Terminal to Detect Vulnerabilities
Anthropic has released a free security-guidance plugin for its Claude Code terminal tool that autonomously reviews code edits, model outputs
cybersecuritynews.com·11h agowolfCOSE: A Lightweight COSE + CBOR Library for Embedded Systems with PQC and FIPS 140-3 Support
wolfCOSE is a lightweight C library implementing CBOR (RFC 8949) and COSE (RFC 9052/9053) for embedded systems, using wolfSSL as the crypto
Anthropic launches Claude Security beta for codebase vulnerability scanning
Anthropic has released Claude Security, a defensive security tool within Claude Code on the web, from closed preview to beta for Claude Ente
thenewstack.io·1d agoHow LinkedIn's 2012 Breach Exposed the Dangers of Unsalted Password Hashes
This article examines the 2012 LinkedIn breach where attackers cracked millions of passwords using fast, unsalted hashes like MD5 and SHA-1.
hendryadrian.com·2d agoAI-Generated npm Package Leaks Its Own GitHub Token, Exposing Malware Operator
A malicious npm package named mouse5212-super-formatter, identified by OX Security, was caught leaking its own hardcoded GitHub token. This
