Closed phaupt closed 2 years ago
I implemented support for signature validation for the 4 discussed aspects:
I updated the documentation to provide details on this new feature. I also updated the CLI mode to provide the "-validate" parameter to make the client validate the signature after acquisition.
This new feature is now available in v1.5.0 of the Mobile ID client, here on GitHub release section as well as on Maven Central.
Awesome work, thank you @bmocanu
To improve security, the received Mobile ID signature response shall be validated.
The truststore.jks example should contain only the root certificates: