tillitis / tkey-verification

Vendor signing and user verification of TKey genuineness
https://www.tillitis.se
GNU General Public License v2.0
42 stars 2 forks source link

Remove all use of the sha256 hash for now #5

Closed mchack-work closed 1 year ago

mchack-work commented 1 year ago

Instead, send the UDI and the public key unhashed to the signer. Sign directly over the public key.

If we later decide to publish something on sigsum we can decide that then and let the signer store something.