Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Meta] Support for Timestamp Protocol verification #1182

Open
4 tasks
DarkaMaul opened this issue Oct 23, 2024 · 1 comment
Open
4 tasks

[Meta] Support for Timestamp Protocol verification #1182

DarkaMaul opened this issue Oct 23, 2024 · 1 comment
Labels
enhancement New feature or request
Milestone

Comments

@DarkaMaul
Copy link

Improve the support of sigstore-python for signing and verification APIs and CLIs for accepting signed time from a TSA versus an artifact transparency log (or both).

Description

We developed a new rfc3161-client to perform the parsing and generation of the Timestamp Request/Response objects.

This set of changes aims to integrate this new client into sigstore-python. We'll split the contributions into several PRs to make their review slightly easier.

/cc @woodruffw @facutuesca

@DarkaMaul DarkaMaul added the enhancement New feature or request label Oct 23, 2024
@woodruffw woodruffw added this to the 3.6 milestone Oct 23, 2024
@jku
Copy link
Member

jku commented Oct 25, 2024

Can I get a short explanation for the use cases:

Support for Timestamp Protocol verification

vs

This field is planned for removal ( [targets v11] What to do with the GitHub TSA in trusted_root.json root-signing#1268 , Signing event: sign/update-targets-1 root-signing-staging#156 )

If the public good instance is not going to support this, is it worth the additional code and dependency in this client?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

3 participants