-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512,SHA1 Date: Fri, 24 Jul 2009 18:59:49 +0000 (ISO 8601 Basic: 20090724185949Z) Title: New Key Statement Author: Ben Love Primarily because of the SHA-1 and the relative insecurity of DSA keys, I've migrated to a new OpenPGP key. I will transition to this new key very quickly. The most unfortunate part is that I only learned about the need for a stronger key after regenerating my last key. The message will be signed by all of my (still valid) keys, past and present, to certify the transition. The date above should match the date on the signatures to the nearest second. The old key(s) are: a) pub 1024D/0x527E30C7E8502888 2007-07-28 [expires: 2009-07-27] Key fingerprint = AEB4 A0AB F5BE 7091 5A45 DF00 527E 30C7 E850 2888 uid Ben Love sub 2048g/0x25AC1DF0A54B06DC 2007-07-28 [expires: 2009-07-27] b) pub 1024D/0xB6401B0002585383 2009-07-13 [expires: 2011-07-13] Key fingerprint = 793E 6234 738D 353C DE0A E4FE B640 1B00 0258 5383 uid Ben Love (Primary) uid Ben Love uid Ben Love uid Ben Love (Work) uid [jpeg image of size 2181] sub 2048g/0xD9F129E3710CF77C 2009-07-13 [expires: 2011-07-13] c) pub 1024D/0xC8377F0756B0DBDA 2009-07-14 [expires: 2010-07-14] Key fingerprint = 8A73 FC81 F351 1625 AEEB F9DB C837 7F07 56B0 DBDA uid Ben Love (Work) sub 2048g/0x90E1E5858462FDD8 2009-07-14 [expires: 2010-07-14] And the new key is: pub 4096R/0x0E9CF26FDAE3284F 2009-07-20 [expires: 2011-07-20] Key fingerprint = 2936 EE16 025B CFEB E043 41E9 0E9C F26F DAE3 284F uid Ben Love (Primary) uid Ben Love uid Ben Love uid Ben Love (Work) uid [jpeg image of size 9727] sub 4096R/0xAE6454D80159CBBD 2009-07-20 [expires: 2011-07-20] sub 4096g/0xF4FE3FE7CC2B2B6A 2009-07-20 [expires: 2011-07-20] sub 4096R/0xDEDABCA933A1263C 2009-07-20 [expires: 2011-07-20] The full new key (including photo uid) is available on my webserver: http://www.kylimar.com/cryptograpy/keys/blove.public.asc Or, you can fetch the key from a public key server: gpg --keyserver pgp.mit.edu --recv-key 0x0E9CF26FDAE3284F This statement, in its entirety and signed, along with any potential future statement(s), will persist at this address: http://www.kylimar.com/cryptography/statements/current.txt.asc I have also recently developed a policy for key certification. You may find the most up-to-date version at this address: http://www.kylimar.com/cryptography/certification-policy/current.txt.asc Thank you for your consideration in this matter. I hope you choose to increase the strength of your keys as well. Regards, Ben -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.1 (GNU/Linux) iQIVAwUBSmoEpQ6c8m/a4yhPAQrjJg/+Kw/SkKpZDYsF4Gqd7OOsgsbWXRVb8kyL 8KQA4ADFZYCxBYMfGGOE4wxF2qw4ndy66izaZa6CXSflsYU9BdUV8XbxOuXRW0UQ UdGAhH3KwejKW3Bxyw4AJiFKuAm68FV9OhEcPVEd84miY+yitYjkLGQltzuXV9AH +JwDNh1xHdrrsJwI6Sp2gTyHQ0cMmmM7QphZXimtlZBEPVv/DMXCqQrA5cHx+sVI GCN2kF80nCPGr70QDD5TGw18aRFLc233GZ/F3YX1iHzvlU3a28F3t7f6dhr5+wcc MLQ7zoHLPTNDGjh1O+L0pDuvxz5Em2ThkmhEUav7uYm/CkmCCgVrezrehP02/CH3 I1P5Iqb1dqmYRBQ3XEuku7d8Zymm9NzCj61q9p5fcZDOe7u+jamy3KVuy36P9huW XZK4WTYyHkbXBYuSFxqpxfWYlCTcT84NpjYu1tgxHbOGsN16I8/x5J7o2wVpBymy EKW8v4t32lrW2YlrLHprJ69JZiAddNw6UwT6TrDyMCoUsejataddrLIMsFaXo6Yw 0V5XKJvglIYV8pQo63z8bx6cY9s2DJiTZZw2lD1VRpr5OLGx4KY/ObBGAN+es1nh XBrVqQTDDhvzJwnmddNMP6kRPlhlBF5GQ2gyGRpayc0orTW7pnlb4vAZ/DERToDg Fm/v23kIyTqIPwMFAUpqBKVSfjDH6FAoiBEC1NUAn3I7XZu9LBSwgUF3hE8sXuEG /0thAKCe4vKvHhmXMfMKlWkm+VY/S5+8mog/AwUBSmoEpbZAGwACWFODEQLU1QCg 3YySlTXN/OO4qp1YAi0chYZ0hSEAniqKzLzsMq/Gxm/+GCQjyEhWAcPfiD8DBQFK agSlyDd/B1aw29oRAtTVAJ4wT35wpEH/ET8hJMGmKTlJKLbjvgCfWI0wDQxz0hwq S08eeqhpMik6Gyw= =OTWS -----END PGP SIGNATURE-----