Correct enforcing fingerprint #764
Labels
csaf 2.1
csaf 2.1 work
editor-revision
already worked on in the editor revision
editorial
mostly nits and consistency
Currently, it is possible to add a OpenPGP key to a PMD without adding the fingerprint:
Quoting from https://docs.oasis-open.org/csaf/csaf/v2.0/provider_json_schema.json
The schema does not enforce the fingerprint, which is in contrast to Example 124 (see https://docs.oasis-open.org/csaf/csaf/v2.0/os/csaf-v2.0-os.html#717-requirement-7-provider-metadatajson) which is labeled as Minimal but contains a
fingerprint
value.It must be an oversight, that the fingerprint is not
required
per schema. We should correct that.The text was updated successfully, but these errors were encountered: