Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Warning/Error for signature expirations #678

Closed
ctron opened this issue Jan 8, 2024 · 6 comments
Closed

Warning/Error for signature expirations #678

ctron opened this issue Jan 8, 2024 · 6 comments
Assignees
Labels
csaf 2.1 csaf 2.1 work editor-revision already worked on in the editor revision

Comments

@ctron
Copy link

ctron commented Jan 8, 2024

When documents are signed with a key, that key/certificate may expire, making the validation of such signatures problematic.

I believe there should be a grace period in the specification which requires that there is "enough" time left. And while one can argue about the exact number, I think it would make sense to have two requirements in the spec:

  • Signatures MUST be valid for 30 more days
  • Signatures SHOULD be valid for 90 more days
@santosomar
Copy link
Contributor

Comment from the TC (Denny) : "Signatures MUST be valid for at least 30"

@santosomar
Copy link
Contributor

As discussed in the CSAF TC monthly meeting on 2024-02-28, this will be added to the guidance documentation for CSAF 2.0.

tschmidtb51 added a commit to tschmidtb51/csaf that referenced this issue Apr 23, 2024
- addresses parts of oasis-tcs#678
- add FAQ on signing
tschmidtb51 added a commit to tschmidtb51/csaf that referenced this issue Apr 23, 2024
- addresses parts of oasis-tcs#678
- provide tool guidance
@tschmidtb51
Copy link
Contributor

As discussed in the CSAF TC monthly meeting on 2024-04-24, the wording from #724 will be added to CSAF 2.1.

tschmidtb51 added a commit to tschmidtb51/csaf that referenced this issue Apr 24, 2024
- addresses parts of oasis-tcs#678
- add guidance on signing regarding minimum requirement of still valid for 30 days
- add tool guidance
@tschmidtb51 tschmidtb51 added editor-revision already worked on in the editor revision and removed tc-discussion-needed labels May 22, 2024
@tschmidtb51
Copy link
Contributor

@ctron The comments mailing list is now back online. Please formally announce your suggestion there, e.g. through "Please see our suggest in Github Issue XYZ (https://github.com/oasis-tcs/csaf/issues/XYZ)."

Thank you!

@tschmidtb51 tschmidtb51 self-assigned this May 22, 2024
@tschmidtb51 tschmidtb51 added the csaf 2.1 csaf 2.1 work label May 29, 2024
@tschmidtb51
Copy link
Contributor

The issue was suggested on the mailing list: https://groups.oasis-open.org/discussion/warningerror-for-signature-expirations

@tschmidtb51
Copy link
Contributor

The issue was resolved with #723 and #724

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
csaf 2.1 csaf 2.1 work editor-revision already worked on in the editor revision
Projects
None yet
Development

No branches or pull requests

3 participants