ietf-teep / architecture

TEEP architecture draft
5 stars 9 forks source link

Insufficient description for compromised TAM #241

Closed bremoran closed 1 year ago

bremoran commented 2 years ago

https://github.com/ietf-teep/architecture/blob/master/draft-ietf-teep-architecture.md?plain=1#L1326

I'm very concerned that this is not an adequate description of the requirements for validating a TAM. A verification of certificates is inadequate to deal with an Advanced Persistent Threat against a TAM and the consequences are significant. I'd be happy to suggest some additional text.

dthaler commented 2 years ago

@bremoran Can you suggest some additional text?