ukhsa-collaboration / covid-19-app-configuration-public

8 stars 13 forks source link

Sensitive information included in the repo? #1

Closed javixeneize closed 3 years ago

javixeneize commented 4 years ago

Hi

I have seen some information related to certificates and CA included in the repo - https://github.com/nhsx/covid-19-app-configuration-public/blob/master/android/common/src/main/kotlin/EnvironmentConfiguration.kt

Can you check if this is any sensitive information there?

Thanks

paulchambers commented 3 years ago

They are the fingerprints of the public keys of the root certificates that the application trusts.

These are public information published by the certificate authorities

javixeneize commented 3 years ago

Fine then. Thanks for clarifying