Skip to content

Explain why checking some hashes before signatures is ok? #138

@trishankatdatadog

Description

@trishankatdatadog

From this PR on php-tuf, I learned that it is not clear why the spec advises on checking snapshot/targets hashes from timestamp/snapshot before checking signatures. It looks unsafe until it is recalled that the hashes from previously verified snapshot/targets. Recently while independently implementing the spec, even I had some concern until I understood this. Should we clarify this?

HT @tedbow @davidstrauss

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions