Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Define certificate semantics #65

Closed
dlorenc opened this issue Mar 28, 2021 · 1 comment
Closed

Define certificate semantics #65

dlorenc opened this issue Mar 28, 2021 · 1 comment

Comments

@dlorenc
Copy link
Member

dlorenc commented Mar 28, 2021

Basically, resolve my TODO here: https://github.com/sigstore/fulcio/blob/development/pkg/ca/ca.go#L63

We should write this up into a basic spec.

  • What fields must be set for something to be a valid code signing cert by sigstore clients
  • How does expiry work?
  • What "timestamp" proofs are acceptable?
  • How does chain validation work? What can intermediate certs do?

And probably much more!

I know @mmalone talked about this a bit in slack, but can't remember if we got an issue filed somewhere.

@haydentherapper
Copy link
Contributor

Closing, all of these have been decided

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants