Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Support signing over OCSP responses #106

Open
twifkak opened this issue Sep 17, 2018 · 0 comments
Open

Support signing over OCSP responses #106

twifkak opened this issue Sep 17, 2018 · 0 comments
Milestone

Comments

@twifkak
Copy link
Member

twifkak commented Sep 17, 2018

WICG/webpackage#121 will change the SXG signed message to include the OCSP response attached to the cert-chain+cbor. This means that:

  1. Every ~3.5 days, the cert-url will change, to reflect the different OCSP response attached. (Or else old SXGs won't validate any more.)
  2. When signing a document, the packager must request the freshest cert-url from the certcache.
@twifkak twifkak added this to the v4+ milestone Sep 17, 2018
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants