I created a pair of GPG keys to reflect my true identity and am now trying to create a solid reputation around it. My goal is to use a single GPG key (with subkeys) to cover all my online needs and keep it as generic as possible (I use gpg@example.com as my identity).
I've also been using a mail catchall for years to use one mail address per web site, to be able to filter, sort and find the origins of them automatically.
But I find it hard to make the link between the two. For example on github, I use github@example.com as email for commits but as they are signed with gpg@example.com, github marks them as untrusted, even though I have gpg@example.com as verified email on the platform, because of their committer trust model.
So here's the real question: According to the state of the art of GPG keys, what should I do? The options I've thought of so far are:
- Add
github@example.comas an identity on my GPG key pair. But I want the key to be as generic as possible, and if I have to do this for every domain, I'll have to update my GPG key everywhere every time I get a new source. - Like the previous one, but using a copy of the key that has, for each platform, only
gpg@example.comandplatform@example.comas its identity. But I have no idea if this is even possible. - Using
gpg@example.comas a committer, but that breaks my desire to separate email addresses. - Any other viable option.
Probably any of these options could work, but since I'm refactoring my GPG keys and their usage, I'd like to follow the state of the art and not go down an unsafe or insecure way.