rust-tuf icon indicating copy to clipboard operation
rust-tuf copied to clipboard

Should Client::new download the latest metadata?

Open erickt opened this issue 7 years ago • 1 comments

Copying from #157. Client::new right now starts with the first metadata, but that could be years out of date for a long-lived repository. Should it instead try to download the latest version instead?

erickt avatar Sep 04 '18 16:09 erickt

The client should store the latest metadata is has seen and use it when updating. The client should also periodically be updated to ship with recent metadata.

These actions help to prevent old keys that have been compromised from being used to attack clients.

JustinCappos avatar Sep 04 '18 18:09 JustinCappos