PGP key expiration

When you create or upload your PGP keys, make sure that the key's expiration date is set according to the acceptable criteria. The optimal expiration period for a PGP key is less than or equal to 365 days.

PGP key expiration criteria

As part of the validation for a PGP key, make sure that the expiration adheres to the following criteria.
  • Absence of any expiration date for the master key and subkeys is not acceptable.
  • A key that is set to expire after over a year might go unnoticed and pose a security threat. So, if you want to set a PGP key to expire between one to five years, you must acknowledge the risk.
  • An expiration date of more than five years is not acceptable.

As a standard practice, set your PGP key to expire within every 365 days. This condition reduces the security risks that might be associated with setting longer expiration dates for PGP keys.