ch5: outline sketch

This commit is contained in:
Heiko Schaefer 2023-09-23 17:35:22 +02:00
parent 61d5b010f8
commit e5500ac6f8
No known key found for this signature in database
GPG key ID: 4A849A1904CCBD7D

View file

@ -1,8 +1,25 @@
(private_key_chapter)=
# Private key material
# Private keys
```
- Consistently consider private key material as a separate thing from Certificates? (like in pkcs#11?)
- consider KOpenPGP attack
- For TSKs: Best practices S2K + S2K migration?
```
```
## Transferable secret keys
https://www.ietf.org/archive/id/draft-ietf-openpgp-crypto-refresh-10.html#name-transferable-secret-keys
## Private key operations
The core of private key operations doesn't require access to the whole certificate. A private key subsystem only needs to handle the cryptographic key material.
### OpenPGP card for private keys
[OpenPGP card](https://en.wikipedia.org/wiki/OpenPGP_card) devices are a type of hardware security device. They are one popular way to handle OpenPGP private key material. These devices do not store the full OpenPGP certificate.
## Advanced topics
### TSKs: Best practices S2K + S2K migration?
### The KOpenPGP attack