agent-js
agent-js copied to clipboard
[SecReview] NCC-DITY002-012: No Constraint Checks Enforced in Certificate Delegation Validation
Discussion in readout meeting with NCC:
- This is delegation with certificates
- can take valid cert and turn it into a cert whose delegation chain is larger. place it in a delegation field, cause validation process to re-validate the cert.
- Hans: server would have to receive malicious thing from server. → low.