On 5/8/12, Beck Chen <[email protected]> wrote:

> According to the outline, the long-term identity key should be different
> from the
> signing key, which changes every 3-12 months. Then why should the signing
> key
> become the identity key in the descriptor format, and fingerprint become
> the hash
> of the identity key?

The ‘relay identity key’ is not the same as the ‘authority identity
key’.  The ‘relay identity key’ might also be different from the
‘directory signing key’; I'm not sure about that.

Descriptors contain and are signed with the ‘relay identity key’, and
the fingerprint in a descriptor is the hash of the relay identity key.


Robert Ransom
_______________________________________________
tor-dev mailing list
[email protected]
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-dev

Reply via email to