I did create a master key + 3 subkeys for signing, decrypting, authenticate.
The master key has unlimited validity and is well preserved offline.
The 3 subkeys have a limited expiry date.
On my laptops configured for use with Yubikey it looks like this:
Code:
$ gpg2 --list-keys
/home/x11/.gnupg/pubring.gpg
-----------------------------
pub 4096R/A5XXXXXX 2015-12-31
uid [ uneing.] x11 <x11@home.de>
sub 4096R/1EXXXXXX 2015-12-31 [verfällt: 2018-12-29]
sub 4096R/B4XXXXXX 2015-12-31 [verfällt: 2018-12-29]
sub 4096R/52XXXXXX 2015-12-31 [verfällt: 2018-12-29]
(Remark: "verfällt" translates to "expires".)
The secrete keys are only stubs which do not show the expiration dates.
My question now:
How do I manage to extend the validity of my subkeys on the Yubikey?
On the offline machine it is quite easy, because all keys are available and the master key has already unlimited lifetime. For obvious reasons I do not want to create a new set of subkeys and transfer them to the Yubikey overwriting the current ones.
Regards,
x11