issues
search
suit-wg
/
information-model
1
stars
1
forks
source link
Add clarification related to secure clocks
#23
Closed
bremoran
closed
3 years ago
bremoran
commented
3 years ago
Clarified several points:
Remote secure clocks require authentication. This was assumed when using the "correctness guarantees" however that was not sufficiently clear.
Risks associated with using a flawed clock for manifest expiry.
Secure clock can be used for key expiry.
Risk of flawed clock for key expiry is identical to not having key rotation.
Fixes: #11
Clarified several points:
Fixes: #11