kmip-interop-tech — archive
[Date Prev]
| [Thread Prev]
| [Thread Next]
| [Date Next]
— [Date Index]
| [Thread Index]
| [Month Index]
| [List Home]
Revoke
Since private keys are generally used for signing or decrypting, the public key should be moved to deactivated/process only. Revocation is not required because you still may need to use the public key for verification of items that were signed by the revoked/compromised private key. In this fashion you would no longer encrypt with the public key or sign with the private key. And another thought is that depending on the compromise of the private key should determine whether the public key goes to process only or compromised as the public key is very much a known value so compromise doesn't really apply to it. Now I just need to make sure that is what we actually do. Just thinking out loud. Bob L.
[Date Prev]
| [Thread Prev]
| [Thread Next]
| [Date Next]
— [Date Index]
| [Thread Index]
| [Month Index]
| [List Home]