On 5/8/12, Beck Chen csybeck@gmail.com wrote:
According to the outline, the long-term identity key should be different from the signing key, which changes every 3-12 months. Then why should the signing key become the identity key in the descriptor format, and fingerprint become the hash of the identity key?
The ‘relay identity key’ is not the same as the ‘authority identity key’. The ‘relay identity key’ might also be different from the ‘directory signing key’; I'm not sure about that.
Descriptors contain and are signed with the ‘relay identity key’, and the fingerprint in a descriptor is the hash of the relay identity key.
Robert Ransom