这是indexloc提供的服务,不要输入任何密码
Skip to content

NRAS token verification #107

@iflipe

Description

@iflipe

During remote attestation process using NRAS, the token received as result is decoded and the signature is validated using the certificate that comes from the JWKS endpoint to the 'kid' for the token. Is there a reason why the verification stop there? Why not verify the certificate chain in its entirety in case of some attack? Are the remaining certificates up the chain available somewhere if I'd want to check them manually?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions