android icon indicating copy to clipboard operation
android copied to clipboard

support for Minisign prehashed signature format

Open fkooman opened this issue 2 years ago • 0 comments

Minisign 0.10 was released over the weekend and defaults to using prehashed signatures. See here for more information about prehashed signatures. In the future "legacy" signatures will be removed from minisign, so we should probably switch to prehashed signatures a.s.a.p. You could potentially leverage any of the listed implementations if they are of sufficient quality and support prehashing...

The Server Discovery documentation has also been updated to mention prehashed signatures.

Steps:

  • [ ] make sure prehashed signatures are supported
  • [ ] add option to reject non-prehashed signatures, compare to -H flag in Minisign (to be activated in the future)

NOTE: this issue was created in all eduVPN application repositories.

fkooman avatar Oct 11 '21 07:10 fkooman