Skip to content
This repository has been archived by the owner on Apr 26, 2024. It is now read-only.

make it possible to use different signing keys for the notary server and signing events #5351

Closed
richvdh opened this issue Jun 5, 2019 · 2 comments
Assignees
Labels
Security z-p2 (Deprecated Label)

Comments

@richvdh
Copy link
Member

richvdh commented Jun 5, 2019

No description provided.

@richvdh
Copy link
Member Author

richvdh commented Jun 6, 2019

We should probably actually sign notary responses with two keys: the old, compromised key, for compatibility with those who still rely on it, and a new key, who want belt-and-braces security above TLS.

@richvdh
Copy link
Member Author

richvdh commented Jun 27, 2019

This is a thing that we originally wanted to do for v1.0 but ended up having to descope. It's still a security-related thing that we should do asap imho.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
Security z-p2 (Deprecated Label)
Projects
None yet
Development

No branches or pull requests

4 participants