Key lifetime: C2S and S2C

Hal Murray hmurray at megapathdsl.net
Sun Jan 20 01:40:49 UTC 2019


> So enforcing key rollover isn't a concern. The recommended server key
> rotation is primarily about forward secrecy then, I presume. 

Draft says:
                             Erasing old keys provides for forward
secrecy, limiting the scope of what old information can be stolen if
a master key is somehow compromised.


-- 
These are my opinions.  I hate spam.





More information about the devel mailing list