Expand description
What an OpenPGP key says about itself: fingerprint, key id, user ids and, the
reason this exists, when it expires (Phase 24.5, gpg_key).
The expiry of a key is not in the key packet. It is a subpacket (type 9, “key expiration time”, seconds after the key’s creation) of the self-signature that binds a user id or the key itself, so reading it means walking the signature packets. This reads v4 public and secret key blocks, ASCII-armoured or binary, and refuses what it does not understand (v5/v6 keys, partial-length packets) rather than guessing: an expiry that is wrong is worse than none.
Nothing here verifies a signature. The file is the user’s own key and the answer is metadata for a reminder; a forged self-signature could only make the reminder wrong, never grant anything. Secret key material is never read: a secret-key packet’s public portion is parsed and the rest is skipped.