-
Notifications
You must be signed in to change notification settings - Fork 547
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Timestamp authority response verification during signing #2488
Comments
+1 overall -1 to the name |
We can refactor that. This flag will also be unnecessary if you ship the TSA trust roots with TUF. |
@haydentherapper and I discussed this; we decided go with |
@znewman01 I remember we initially used |
I’m working on this now. Yea, I will use certificate-chain |
Removing myself from this if anyone else wants to take it on |
Description
We should verify the response from the timestamp authority when it's received, as per RFC 3161:
We'll need to add the
timestamp-cert-chain
flag for signing.The text was updated successfully, but these errors were encountered: