From: Steven Rostedt
Date: Mon Oct 03 2011 - 05:14:38 EST

On Sat, Oct 01, 2011 at 07:05:19AM -0700, Greg KH wrote:
> I would recommend a physical access device for your new gpg key that you
> create. I've heard good things about this USB device:
> and am trying to have a bunch of them at the Kernel Summit this year to
> hand out to people if they want one.

Hmm, if I'm going to get one at KS, should I stop getting signed keys
now? A few of us have already started the GPG song and dance to get
signed keys over the phone (where we know each other enough to know
phone numbers and recognize voices).

But I did it all wrong. I have a 4k RSA key for both signing and
encrypting with no revoke generated and no expiration. The key is
currently on one of my machines, which I was about to move to an
encrypted usb device.

If I can get one of these devices, it sounds like I should create a new
key on it as my master key and start using subkeys as described in the
debian link that someone posted before. Then at the keysigning I would
just use the key from this device.

> There are also lots of other smart-card form-factor devices that can be
> used to store GPG keys. Some places to purchase these can be found at
> links from the above site.

I just pulled out an old GNU GPG card I had, and unfortunately it only
supports 1024 RSA keys.

-- Steve

