Prompted by the recent vulnerability in SHA-1 and admonitions to begin the process of moving away from that hash function, I'm playing around with GnuPG again. I was just wondering how other folks use the system. Use these questions as prompts, but I'd really like to hear about stuff I haven't even thought of.
What size keys are you using?
What sort of things do you have in your gpg.conf?
Do you have an expiration date on your keys?
Do you have a revocation certificate somewhere safe - perhaps with a trusted friend?