Design 24: the export says what an earlier key opens
This commit is contained in:
@@ -90,8 +90,10 @@ The vault's second job is to hold these, and it does so without holding a value:
|
||||
cannot open. A secret made before the key existed has no such copy and cannot get one, the
|
||||
plaintext being gone; the mesh says which those are rather than letting the export pass for
|
||||
complete.
|
||||
- **The export.** All operator-sealed copies, the key's public half and its fingerprint, and the
|
||||
list of what is not recoverable, as one document. The vault declares that it *keeps* this, and
|
||||
- **The export.** All copies sealed to the mesh's current operator key, the key's public half and
|
||||
its fingerprint, and two honest lists beside them: what is sealed to an earlier key the mesh has
|
||||
since replaced, openable with that key alone, and what has no operator copy at all. As one
|
||||
document. The vault declares that it *keeps* this, and
|
||||
the mesh writes it onto the vault's own disk as an ordinary declared file — ciphertext to the
|
||||
machine that holds it and to the bus it crossed. The same document can be written out by the
|
||||
operator to keep beside the key.
|
||||
|
||||
Reference in New Issue
Block a user