diff --git a/book/source/08-signing_components.md b/book/source/08-signing_components.md index 8fa627c..350efdb 100644 --- a/book/source/08-signing_components.md +++ b/book/source/08-signing_components.md @@ -398,7 +398,7 @@ In OpenPGP, certain subpackets are universally expected across all types of sign * **Issuer Fingerprint**: Essential for signature verification, this subpacket identifies the key (or subkey) used to create the signature. OpenPGP v6 signatures should include the Issuer Fingerprint subpacket, containing the 32-byte fingerprint of the key. ```{note} -The issuer key might be a subkey. +The key used as the issuer in the signature might be a subkey of the primary key. ``` This subpacket can be placed in either the hashed or unhashed area due to its self-authenticating nature. However, it is recommended to include it in the signature's hashed area for enhanced security.