I'm working on a school project, including Public Key Infrastrucure (PKI).
We are instructed to get out how long the validity period of a GPG-key
should be set in a company or other organisations the info-material we collect
is for.

First I wanted to advise a unrestricted validity, but then I remembered that
organisations or enterprises might have often changing memebers. So I'm caught
between the devil and the deep blue sea what to advise...

I tried to find out with Google, but there aren't any publications including
these information.

Thanks for any advises or experiences!


PS: My english is quite bad but I hope all necessary information can be
    understood ;)

