Immediately after creating a GnuPG key pair you want to produce the revocation certificate for the key whose ID is A1B2C3D4, so that you can withdraw the key later even if you lose the passphrase. Type the gpg command, with no output-file option.

LPIC-1 Exam 102-500, objective 110. Security hard

Draft — not checked yet. This question was written from the published exam objectives and cites the clause it comes from, but nobody has yet read it against that clause and signed for it.

It is kept out of search results and out of mock exams until they have. Read the source below before you take the answer as settled.

Answer

Type the answer.

Accepted answers

Case sensitive — Linux is, and grading LS as ls would teach a falsehood.

Why

A revocation certificate is generated once, ideally at key creation time, and stored somewhere safe and offline: publishing it is what tells the world the key must no longer be used. In GnuPG 2.1 and later the canonical spelling is --generate-revocation, with --gen-revoke kept as the shorter alias; add `--output revoke.asc` to write it to a file rather than the terminal. Recent versions also drop a pre-made revocation certificate into ~/.gnupg/openpgp-revocs.d when a key is created. The rest of your GnuPG state lives under ~/.gnupg too: the public keyring pubring.kbx, secret keys under private-keys-v1.d, and the trust database trustdb.gpg. After revoking, push the updated key to a key server with `gpg --keyserver <server> --send-keys A1B2C3D4`.

Where this comes from

Cited
LPI exam objective 110.3
What it says
Create a revocation certificate for a GnuPG key and know where GnuPG stores its keyrings.

Practise this

Reading one question is not practice. The trainer will draw a set from objective 110 and space the ones you get wrong.

Practise LPIC-1 Exam 102-500