Browse Source

a few more thoughts about seeds

svn:r3399
Roger Dingledine 20 years ago
parent
commit
01cd23ef62
1 changed files with 6 additions and 2 deletions
  1. 6 2
      doc/dir-spec.txt

+ 6 - 2
doc/dir-spec.txt

@@ -106,8 +106,12 @@ Piece two: (optional)
   and not fingerprints, it also means that dirservers can rotate their
   signing keys transparently.
 
-  But, keeping track of the seed keys becomes a critical security issue;
-  and rotating them in a backward-compatible way adds complexity.
+  But, keeping track of the seed keys becomes a critical security issue.
+  And rotating them in a backward-compatible way adds complexity. Also,
+  dirserver locations must be at least somewhere static, since each lost
+  dirserver degrades reachability for old clients. So as the dirserver
+  list rolls over we have no choice but to put out new versions.
+
 
 Piece three: (optional)