ietf-openpgp
[Top] [All Lists]

Re: [openpgp] Fingerprint schemes versus what to fingerprint

2016-04-07 06:03:08
Bryan Ford <brynosaurus(_at_)gmail(_dot_)com> writes:

DKG  brought up the question of whether that octet-string should still
include the Unix timestamp like it currently does.

Definitely not.  What you want is a means of generating a unique lookup key
(e.g. for a database or hash table) that locates a public key.  By mixing a
nonce, the timestamp, into the calculation, you lose the uniqueness, and in
fact the locatability, because the search key is no longer just a hash of the
public key but a hash of the public key and some other metadata that you may
or may not have.

Peter.

_______________________________________________
openpgp mailing list
openpgp(_at_)ietf(_dot_)org
https://www.ietf.org/mailman/listinfo/openpgp