mirror of
https://codeberg.org/openpgp/notes.git
synced 2025-09-09 11:19:41 +02:00
ch4: move certificate validity up
This commit is contained in:
parent
04be4cd927
commit
6a14882687
1 changed files with 12 additions and 12 deletions
|
@ -305,6 +305,18 @@ The popular [SKS keyserver network experienced certificate flooding firsthand](h
|
|||
|
||||
## Advanced topics
|
||||
|
||||
### When are certificates valid?
|
||||
|
||||
- Full certificate: Primary revoked/key expired/binding signature expired,
|
||||
- Subkey: Revoked/key expired/binding signature expired
|
||||
- User ID: revoked, binding expired, ...
|
||||
|
||||
```{admonition} TODO
|
||||
:class: warning
|
||||
|
||||
write, link to chapter 9
|
||||
```
|
||||
|
||||
(append-only)=
|
||||
### Certificates are effectively append-only data structures
|
||||
|
||||
|
@ -484,18 +496,6 @@ Note that regardless of the OpenPGP version, software that relies on 8-byte Key
|
|||
|
||||
The historical 4-byte "short Key IDs" format should not be used anywhere, anymore (finding collisions in a 32-bit keyspace has been [trivial for a long time](https://evil32.com/)).
|
||||
|
||||
### When are certificates valid?
|
||||
|
||||
- Full certificate: Primary revoked/key expired/binding signature expired,
|
||||
- Subkey: Revoked/key expired/binding signature expired
|
||||
- User ID: revoked, binding expired, ...
|
||||
|
||||
```{admonition} TODO
|
||||
:class: warning
|
||||
|
||||
write, link to chapter 9
|
||||
```
|
||||
|
||||
(cert-freshness)=
|
||||
### Certificate freshness: Triggering updates with expiration
|
||||
|
||||
|
|
Loading…
Add table
Add a link
Reference in a new issue