New CERT® Coordination Center (CERT/CC) PGP Key

The CERT/CC has generated a new PGP key. We use this key to sign all outgoing email, including documents sent to this list. Effective immediately, this new key is available and will be valid until Monday, November 1, 2004. To obtain further information or to download the new CERT/CC public PGP key, please visit

http://www.cert.org/contact_cert/encryptmail.html
or
https://www.cert.org/contact_cert/encryptmail.html

The passphrase used to protect the previous CERT/CC PGP key was accidentally exposed to a small number of non-CERT/CC personnel with whom we have a close working relationship. We have no reason to believe the encrypted form of the private key was exposed in any way, but in accordance with good key management practices, we have generated a revocation certificate for the previous PGP key. The revocation certificate for PGP key id 0x3D2BFD15 has also been included here and sent to the public PGP key servers.

If you have any questions or comments regarding this information, please contact our hotline at +1 412-268-7090 or email us at cert@cert.org.


This document is available from: http://www.cert.org/pgp/newpgp2003.html

CERT/CC Contact Information

Email: cert@cert.org
Phone: +1 412-268-7090 (24-hour hotline)
Fax: +1 412-268-6989
Postal address:
CERT Coordination Center
Software Engineering Institute
Carnegie Mellon University
Pittsburgh PA 15213-3890
U.S.A.

CERT/CC personnel answer the hotline 08:00-17:00 EST(GMT-5) / EDT(GMT-4) Monday through Friday; they are on call for emergencies during other hours, on U.S. holidays, and on weekends.

Using encryption

We strongly urge you to encrypt sensitive information sent by email. Our public PGP key is available from

If you prefer to use DES, please call the CERT hotline for more information.

Getting security information

CERT publications and other security information are available from our web site

* "CERT" and "CERT Coordination Center" are registered in the U.S. Patent and Trademark Office.


NO WARRANTY
Any material furnished by Carnegie Mellon University and the Software Engineering Institute is furnished on an "as is" basis. Carnegie Mellon University makes no warranties of any kind, either expressed or implied as to any matter including, but not limited to, warranty of fitness for a particular purpose or merchantability, exclusivity or results obtained from use of the material. Carnegie Mellon University does not make any warranty of any kind with respect to freedom from patent, trademark, or copyright infringement.


Conditions for use, disclaimers, and sponsorship information

Copyright 2002, 2003 Carnegie Mellon University.