السلام عليكم ورحمة الله وبركاته
استفساري عن تقنية pretty good privacyاريد فهم خوارزمية تقييم للevaluates a public-key certificate
When PGP evaluates a public-key certificate, it goes through the following algorithm5:
1. For each signature do
//scan signatures
2. if signature is completely valid
3. if key trust Î {undefined,unknown,untrusted}
4. ignore signature
5. if key trust is marginal
6. accumulate marginal_counter
7. if key trust is complete
4PGP allows users to have files representing multiple ‘key rings’ to store public or secret keys.
5This algorithm represents a high level observation of how PGP evaluates the certificate, and was not
in any way confirmed with the programmers of PGP for its approximation to the real algorithm that
was implemented in PGP.
8. accumulate complete_counter
9. else
10. ignore signature
// decision
11. if (marginals_counter>0) or (completes_counter>0)
12. if (marginals_counter>=MARGINALS_NEEDED) or
13. (completes_counter>=COMPLETES_NEEDED)
14. mark key validity as 'complete'
15. else
16. mark key validity as 'marginal'
Further clarification:
line 6: marginal_counter accumulates the number of marginally trusted signatures for this key
certificate.
line 8: complete_counter accumulates the number of completely trusted signatures for this key
certificate.
line 10: signatures that are not completely valid are ignored, even when its trustworthiness as an
introducer is defined.
lines 11,12,13: MARGINALS_NEEDED and COMPLETES_NEEDED are explained in section 3.2.
If neither minimum-signature requirements are met, but at least one of them totals more than 16, then
the key is deemed marginally valid (line 16
).
اتمنى توضيح كيف يتم التقيم للمفتاح وشكرا؟؟؟