Skip to content

Explanation

Why these packages are shaped the way they are.

Start here

Concepts

  • Why ECDH, not RSA — the constraint that decided the whole design, and why it is not a limitation of any one key service.
  • The fingerprint binding — why certificate assembly and message decryption cannot be developed or tested apart.
  • Why two keys — an agreement key cannot sign its own binding signature, so a certificate structurally needs two.
  • The role split — why the credential that reads reports must not be able to issue certificates.
  • What a certificate claims — the subpackets a certificate carries, what each one changes about a sender's behaviour, and what omitting one costs you silently.

Components