[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]

Re: http://outel.org/mix/minion/



On Wed, Apr 21, 2004 at 11:34:15AM +0200, Evert Meulie wrote:
> Maybe a FAQ, but why do quite some servers (but not all) have 2
> ServerDesc's listed?

Because of key rotation.  When a server is going to change its key
soon, it sends the directory server a server descriptor including the
new key, and the dates over which the new key is valid.  The directory
server includes the old and the new descriptors until the old one has
expired.

If you look closely, you'll notice that the server descriptors have
different lifetimes (Valid-After and Valid-Until dates), and different
keys.

Yours,
-- 
Nick Mathewson

Attachment: pgp00011.pgp
Description: PGP signature