On Tue, 5 Sep 2000, Ted Lemon wrote:

>
>If you sign the revocation certificate in the compromised key, then
>the only way it can get revoked is if the owner of the key revokes it
>or it's been compromised...
>
>                              _MelloN_


This is true, and that's a *sufficient* condition for a revocation. 
I don't know about you though, but my keyring exists in only two 
copies -- the Red Diskette and the Blue Diskette.  If someone 
manages to grab both Diskettes, I won't be able to use the key 
to issue a revocation certificate. So I would prefer to work with 
a CA where it is not a *necessary* condition for a revocation. 

                                Bear






Reply via email to