python-ndn icon indicating copy to clipboard operation
python-ndn copied to clipboard

LVS Key Suggestor does not return trust anchor

Open tianyuan129 opened this issue 3 years ago • 1 comments

The highlighted piece of code avoids returning all self-signed certificates.

# This is to avoid self-signed certificate
if (not cert.signature_info or not cert.signature_info.key_locator
        or not cert.signature_info.key_locator.name):
    continue

If trust anchor is in the keychain, the key suggestor never returns it even if it's a valid signer.

tianyuan129 avatar Nov 12 '22 10:11 tianyuan129

This is because the design and implementation of the suggest function did not consider the use by controller. To add more context: this code is added to fix the problem that the function may return a self-signed certificate that is not the trust anchor but satisfies the trust schema's check, as we only check packet name vs cert name, but not further move to cert name vs cert's signer.

zjkmxy avatar Nov 12 '22 10:11 zjkmxy