Thank you for the explanation.

On Fri, Aug 11 2017, Jonathan McDowell wrote:

> * If you don't want to buy hardware, use an offline master
> key. Create
> a certification only master key using something like PGP Clean Room
> on a non-networked host [...]

By default, GnuPG creates a signing+certification master key. Could you
explain why it's a good idea to override that? I'm not sure what it

Sean Whitton

