Zack Newman
Zack Newman
Yeah the one time use was just for client keys. That’s the really important part for the long term—the transparency log binds the keys to a timestamp using symmetric crypto....
What's the relationship between this issue and https://github.com/theupdateframework/go-tuf/issues/329 ?
CC @jku to make sure the new python-tuf code is right; in particular: 1. there's no built-in support for consistent snapshots, right? 2. is there a better way to make...
@jku: > Left some comments hopefully they are helpful Yes, thank you for the quick review :smile: great context > Maybe more accurate to say Metadata API does not enforce...
Filed #232 for TAP-12. I think we should probably block this PR on that issue. That would make sure we don't half-implement TAP-12 and accidentally fail-open.
Yup! Might be a week-ish until I get around to it.
Go for it! Let me know if you don’t find time,it had finally popped to the top of my TODO list this week but happy to have you take it...
LGTM though I can't review it since it's my PR
I can probably take this next week.
Oops, looks like promising this week was overly ambitious, but I should have time next week (week of Feb 21)