kmip-interop-tech — archive
[Date Prev]
| [Thread Prev]
| [Thread Next]
| [Date Next]
— [Date Index]
| [Thread Index]
| [Month Index]
| [List Home]
Revoke
As a note, this discussion doesn't just apply to public-private key pairs, but to all manner of linked objects; Compromise of a private key can also affect certificates, while compromise of key derivation data can affect derived keys.
> the public key is very much a known value so compromise doesn't really apply to it. I'd argue that what's actually being compromised is the key pair as a whole. For compromises, as with rekeying, dividing the key pair into its components and attempting to handle them separately doesn't make a lot of sense. Also, users of the public key may/should not have access to the private key and its attributes. If it is desirable for them to distinguish between "a key pair, no longer in use", and "a key pair, no longer trustworthy", then this has to be done via the attributes of the public key; I believe setting the State of the public key to Compromised is the simplest way of doing this.
--
Michael
[Date Prev]
| [Thread Prev]
| [Thread Next]
| [Date Next]
— [Date Index]
| [Thread Index]
| [Month Index]
| [List Home]