Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

GitHub TSA certificate is expired? #1389

Closed
lsd-cat opened this issue Oct 8, 2024 · 1 comment
Closed

GitHub TSA certificate is expired? #1389

lsd-cat opened this issue Oct 8, 2024 · 1 comment
Labels
question Further information is requested

Comments

@lsd-cat
Copy link

lsd-cat commented Oct 8, 2024

While loading trusted_root.json and parsing it, I am trying to verify the certChain for Fulcio and the TSA.

According to both the repository and TUF, it looks like the bottom certificate in the trust chain has expired on "April 13, 2024".

Does it matter? In the end, to verify Sigstore artifacts is it even worth to verify the trust chain rather than just loading the bottom public key of each chain if it came from TUF for verification?

@lsd-cat lsd-cat added the question Further information is requested label Oct 8, 2024
@lsd-cat
Copy link
Author

lsd-cat commented Oct 8, 2024

Seen now #1268

@lsd-cat lsd-cat closed this as completed Oct 8, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
question Further information is requested
Projects
None yet
Development

No branches or pull requests

1 participant