Design 24: the export says what an earlier key opens
This commit is contained in:
@@ -90,8 +90,10 @@ The vault's second job is to hold these, and it does so without holding a value:
|
|||||||
cannot open. A secret made before the key existed has no such copy and cannot get one, the
|
cannot open. A secret made before the key existed has no such copy and cannot get one, the
|
||||||
plaintext being gone; the mesh says which those are rather than letting the export pass for
|
plaintext being gone; the mesh says which those are rather than letting the export pass for
|
||||||
complete.
|
complete.
|
||||||
- **The export.** All operator-sealed copies, the key's public half and its fingerprint, and the
|
- **The export.** All copies sealed to the mesh's current operator key, the key's public half and
|
||||||
list of what is not recoverable, as one document. The vault declares that it *keeps* this, and
|
its fingerprint, and two honest lists beside them: what is sealed to an earlier key the mesh has
|
||||||
|
since replaced, openable with that key alone, and what has no operator copy at all. As one
|
||||||
|
document. The vault declares that it *keeps* this, and
|
||||||
the mesh writes it onto the vault's own disk as an ordinary declared file — ciphertext to the
|
the mesh writes it onto the vault's own disk as an ordinary declared file — ciphertext to the
|
||||||
machine that holds it and to the bus it crossed. The same document can be written out by the
|
machine that holds it and to the bus it crossed. The same document can be written out by the
|
||||||
operator to keep beside the key.
|
operator to keep beside the key.
|
||||||
|
|||||||
Reference in New Issue
Block a user