On Mon, 18 Jul 2005 11:36:20 +0200, Steinar H Gunderson said:

> Well, s/both/all/. What is the disadvantage, if any?

Overhead in size and performance.

> Does it make much more sense having multiple subkeys, but in reality only use
> one of them? I'm not sure if I catch the logic here :-)

The subkeys are used for different operations (sign, authenticate,
encrypt) and for key-rollover (to achieve a certain amount of PFS
(perfect forward secrecy)).  The latter actually requires that one
does not encrypt to any older subkeys even if they are still valid -
the owner of the key might have already deleted that key.

Please continue the discussion on [EMAIL PROTECTED]  I don't think it is
appropriate for a BTS.


Salam-Shalom,

   Werner



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to