I gave up on separating master keys and deriving dedicated signing and encryption subkeys as gpg(2) UI is painful.
Instead I am going for keys with limited lifetimes and are replacing keys on an anual base. I.e., please check back for fresh keys every year.
DESY address: S/MIME X509 : Public GPG Key
GPG fingerprint: | FDC3 3F33 3111 E414 991A 139 BA81 1823 B815 2332 |
---|
GPG fingerprint: | 5B60 1573 0BBC AB8D 75B7 D85E FB15 42F9 91E7 46DC |
---|