diff --git a/03-DESIGN/01-to-be/24-the-secrets-vault.md b/03-DESIGN/01-to-be/24-the-secrets-vault.md index ff05586..badb34a 100644 --- a/03-DESIGN/01-to-be/24-the-secrets-vault.md +++ b/03-DESIGN/01-to-be/24-the-secrets-vault.md @@ -90,8 +90,10 @@ The vault's second job is to hold these, and it does so without holding a value: cannot open. A secret made before the key existed has no such copy and cannot get one, the plaintext being gone; the mesh says which those are rather than letting the export pass for complete. -- **The export.** All operator-sealed copies, the key's public half and its fingerprint, and the - list of what is not recoverable, as one document. The vault declares that it *keeps* this, and +- **The export.** All copies sealed to the mesh's current operator key, the key's public half and + its fingerprint, and two honest lists beside them: what is sealed to an earlier key the mesh has + since replaced, openable with that key alone, and what has no operator copy at all. As one + document. The vault declares that it *keeps* this, and the mesh writes it onto the vault's own disk as an ordinary declared file — ciphertext to the machine that holds it and to the bus it crossed. The same document can be written out by the operator to keep beside the key.