Guten Tag, Peter Sylvester schrieb:
With the first use case (long-term archiving) we address user signatures of data in the archive as well as signatures in (archive)timestamps. So the re-signing is done by the archive service.Guten Abend, I have a problem with the first important use case concerning archiving. I am not sure what is actually what kind of signatures are addressed here.- An archive service can have internal signatures or signatures on attestationsconcerning that data that are archived.- user signatures of data in archive, i.e. the archive stored signed documents.Which means also who is supposed to re-sign, time stamp or whatever.
Of course when verifying the internal signatures of the archive service (e.g. signatures on attestations), the validity of the used algorithms can also be checked, but I think, that is covered by our second use case (signing and verifying).
Regards Thomas
Attachment:
smime.p7s
Description: S/MIME Cryptographic Signature