oasis-tcs / csaf

OASIS CSAF TC: Supporting version control for Work Product artifacts developed by members of TC, including prose specifications and secondary artifacts like meeting minutes and productivity code
https://github.com/oasis-tcs/csaf
Other
151 stars 40 forks source link

Documentation of public_openpgp_keys #709

Open wurstbrot opened 8 months ago

wurstbrot commented 8 months ago

Hello TC,

In the course of integrating a CSAF trusted provider into the Juice Shop, I encountered a reference to cryptographic material, public_openpgp_keys, in the provider-metadata.json file. Notably, public_openpgp_keys is structured as an array.

However, I was unable to locate documentation clarifying the following points:

santosomar commented 8 months ago

Thank you so much for opening this issue! You are right, the spec documentation doesn't go into detail.

We can certainly provide this in our FAQ and/or guidance documentation.