agent-js icon indicating copy to clipboard operation
agent-js copied to clipboard

[SecReview] NCC-DITY002-012: No Constraint Checks Enforced in Certificate Delegation Validation

Open hansl opened this issue 4 years ago • 0 comments

Discussion in readout meeting with NCC:

  • This is delegation with certificates
  • can take valid cert and turn it into a cert whose delegation chain is larger. place it in a delegation field, cause validation process to re-validate the cert.
  • Hans: server would have to receive malicious thing from server. → low.

hansl avatar Apr 03 '21 21:04 hansl