Skip to content

Conversation

@mrvanes
Copy link
Contributor

@mrvanes mrvanes commented Jun 27, 2023

This PR tries to verify metadata signature based on CA signed signing certificate if verification cert is CA cert.

@mrvanes
Copy link
Contributor Author

mrvanes commented Jun 27, 2023

SURFscz/SRAM-deploy#455

@mrvanes
Copy link
Contributor Author

mrvanes commented Jul 11, 2023

Added two tests: the happy flow and the end-entity has CA=true flow, although it's not possible to not trigger the pkix validation in the latter case due to the nature of the verification (we need to supply the self-signed metadata cert, which has CA=true in that case).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants