Closed ianhundere closed 1 week ago
Hey Ian, I like this idea! Would this make sense as a utility in the fulcio or timestamp-authority repositories? I want to make sure the generated certificates are conformant with the Fulcio/RFC3161 standards respectively, and if you're planning to leverage libraries from these repositories already, then maybe it'd be easiest to have them maintained under their respective repos.
hey Hayden, that definitely makes more sense.
i wasn't planning on leveraging libraries from those respective repos, but it looks like there's some overlap.
maybe have a utility with the expected cert standards (e.g. fulcio/rfc3161) and each lives in its respective repo?
lemme know, and i can open an issue for each respective repository and pivot there for discussing further.
btw, thanks for the quick response / feedback!
@haydentherapper / @bobcallaway
should i create a PR in each respective repo:
or should we have it just live in the fulcio repo w/ the expectation that someone can grab it there if needed for tsa ?
In each repo is good with me, I'll review the PRs.
sounds good / i'll open issues there and should have PRs up by the end of the week.
Description
cross posting this from https://github.com/sigstore/helm-charts/issues/863 as i'm thinking something like this would best live here.