ietf-openpgp
[Top] [All Lists]

Re: rfc2440bis-02 comments

2000-12-26 22:38:24

  -keys expire from servers by default.  perhaps 6 months or 1 year.

Removing from keyserver is bad idea. After public key was issued,
there are two status for public keys which are "Valid" or "Not-Valid"
(removked).

Alice, Bob and Olive story.

 Step 1: Alice distribute her public key to the world for verifying
        her signed text by everyone.

 Step 2: Alice sign text and distribute signed text to the world.

 Step 3: Bob get Alice's public key and verify Alice's signed text.
         Bob is certain that this text was written by Alice.

 Step 4: Alice remove her public key from all of the world.

 Step 5: Olive get Alice's signed text. But she can't get Alice's 
         public key and can't verify Alice's signed text.
         Olive is not certain that this text was written by Alice.

 Step 6: Bob says "this is Alice's text", Olive says "I'm not sure 
         this is Alice's text".

This is a kind of chaos. 
                                        --hironobu

<Prev in Thread] Current Thread [Next in Thread>