mirror of
https://codeberg.org/openpgp/notes.git
synced 2025-09-09 11:19:41 +02:00
use updated diagrams
This commit is contained in:
parent
2739b01b4b
commit
61e0846b94
3 changed files with 5 additions and 6 deletions
|
@ -82,7 +82,7 @@ Component keys containing private key material also include metadata specifying
|
|||
|
||||
Each OpenPGP component key possesses an *OpenPGP fingerprint*. This fingerprint is derived from the public key material, the creation timestamp, and, when relevant, the ECDH parameters.
|
||||
|
||||
```{figure} diag/Fingerprint.png
|
||||
```{figure} diag/Fingerprint.svg
|
||||
:name: fig-fingerprint
|
||||
:alt: Depicts a box with white background and the title "Fingerprint of an OpenPGP component key". Inside, another box with a green frame, the title "Component Key", the text "key creation time" on the lower left and a the green public key symbol on the lower right is shown. Below the component key box a fingerprint in a box with a light-yellow background and a yellow dotted line is depicted. The word "Fingerprint" is shown left of the box with the fingerprint and both are connected with a yellow dotted line.
|
||||
|
||||
|
|
|
@ -18,7 +18,7 @@ This chapter is about the remaining counterpart to the elements of certificates:
|
|||
|
||||
In this book, we treat the private key material as logically separate from the OpenPGP certificate. A separate subsystem typically handles operations that use private key material. It is useful to think about OpenPGP certificates on one hand, and the associated private key material, on the other, as related but separate elements[^pkcs11]:
|
||||
|
||||
```{figure} diag/OpenPGPCert_with_privatekeystore.png
|
||||
```{figure} diag/OpenPGPCert_with_privatekeystore.svg
|
||||
:name: fig-openpgp-certificate-with-private-key-store
|
||||
:alt: Depicts a diagram on white background with an OpenPGP Certificate and a private key store. Gray dotted lines connect the green public key symbols of the OpenPGP Certificate with red dotted private key symbols in the private key store.
|
||||
|
||||
|
@ -33,7 +33,7 @@ However, there is one exception. The cryptographic private key material is somet
|
|||
|
||||
Sometimes it is useful to handle OpenPGP certificates combined with private key material in the form of [*transferable secret keys (TSK)*](https://www.ietf.org/archive/id/draft-ietf-openpgp-crypto-refresh-11.html#name-transferable-secret-keys). Transferable secret keys are a serialized format that combines OpenPGP certificate data with the connected private key material, stored in a single file.
|
||||
|
||||
```{figure} diag/TSK.png
|
||||
```{figure} diag/TSK.svg
|
||||
:name: fig-transferable-secret-key
|
||||
:alt: Depicts a box on white background with the title "Transferable secret key". It is identical to the figure depicting an OpenPGP certificate, with the exception, that in each component key box, below the green public key symbol, also the red dotted private key symbol is shown.
|
||||
|
||||
|
|
|
@ -77,10 +77,9 @@ This version of Alice's certificate contains just two packets:
|
|||
|
||||
This is the shape of the packets we'll explore in the subsequent sections:
|
||||
|
||||
```{figure} diag/pubcert-minimal.png
|
||||
```{figure} diag/Minimal_OpenPGP_certificate.svg
|
||||
:name: fig-public-certificate-minimal
|
||||
:alt: TODO
|
||||
:width: 40%
|
||||
|
||||
A minimal OpenPGP certificate, visualized
|
||||
```
|
||||
|
@ -366,7 +365,7 @@ The hash digest is calculated from the following data (see [Computing Signatures
|
|||
|
||||
The signature is calculated from this hash digest.
|
||||
|
||||
```{figure} diag/direct_key_signature_packet.png
|
||||
```{figure} diag/direct_key_signature_packet.svg
|
||||
:name: fig-direct-key-signature-packet
|
||||
:alt: Depicts a box with white background, title "Signature packet" and subtitle "Direct Key Signature (type ID 0x1F)". In the center a box with white background and yellow frame is shown. Inside it several items are listed, separated by yellow dotted horizontal lines. The first three are "Version", "Public-Key Algorithm" and "Hash Algorithm". The fourth item is called "Hashed area" and confines further sub-items by a light-yellow frame on the top and left side. The sub-items are "Signature Creation Time", "Key Expiration Time", "Preferred Symmetric Ciphers for v1 SEIPD", "Preferred Hash Algorithms", "Key Flags", "Features" and "Issuer Fingerprint". The fifth item is named "Unhashed area" and again introduces an area for sub-items, this time using a light-gray border on the top and left side. The unhashed area has no sub-items though. The last item is called "Cryptographic Signature", with the subtitle "by the primary key over primary key, subkey and signature metadata" and includes the green cryptographic signature symbol on the right side.
|
||||
|
||||
|
|
Loading…
Add table
Add a link
Reference in a new issue