You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The encrypted private keys are stored on the Luca Server.
Given that culture4life GmbH and the parties contracted to operate the Luca infrastructure at any time do have access to Luca Server, this would immediately break the promise, that Luca has no access to the data protected by the Health Departments' key pair. Private keys must not be stored in infrastructure owned or operated by an intermediary or they cannot be considered private anymore.
What is the rationale behind storing the Health Departments' private keys on Luca owned infrastructure?
You are stating
Given that culture4life GmbH and the parties contracted to operate the Luca infrastructure at any time do have access to Luca Server, this would immediately break the promise, that Luca has no access to the data protected by the Health Departments' key pair. Private keys must not be stored in infrastructure owned or operated by an intermediary or they cannot be considered private anymore.
What is the rationale behind storing the Health Departments' private keys on Luca owned infrastructure?