Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

sign: Plumb TUF root into sign path for verification #2511

Open
asraa opened this issue Dec 6, 2022 · 0 comments
Open

sign: Plumb TUF root into sign path for verification #2511

asraa opened this issue Dec 6, 2022 · 0 comments
Labels
enhancement New feature or request

Comments

@asraa
Copy link
Contributor

asraa commented Dec 6, 2022

Description

@znewman01 brings this up in this comment: #2393 (comment)

Currently, we have:

  1. TUF root being internally called inside VerifySCT for CT pubkey, which is called on the sign path.
  2. doUpload using a Rekor pubkey (from the API in that PR) to verify the uploaded response
  3. NO Fulcio cert chain validation on the sign path.

All three of these should be addressed, maybe by adding a new struct into either the signopts or keyopts

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

1 participant