I gave up on separating master keys and deriving dedicated signing and encryption subkeys as gpg(2) UI is painful.
Instead I am going for keys with limited lifetimes and are replacing keys on an anual base. I.e., please check back for fresh keys every year.
DESY address: S/MIME X509 : Public GPG Key
GPG fingerprint: | EEAA 22E9 1327 7FF1 A805 8F46 45CC BF6C EBF2 70E4 |
---|
GPG fingerprint: | C01E 0C1D 8F8A F8AB 1854 C723 B513 2833 C6D9 1E2D |
---|