+
Skip to content

detached signatures (allow multiple people to sign the security.txt) #206

@herbetom

Description

@herbetom

Is your feature request related to a problem? Please describe.
It would be really helpfull if more then one signature could be used to verfify the content of the security.txt

For smaller projects you might not want to go through the effort of managing a common address and a common gpg key, but just list the email addresses of several people involved in the project as Contact. Under Encryption you link the appropriate public keys and you have a security.txt relatively quickly.

But now it would be nice if more than one person could sign the security.txt and it would not be limited to one signature. So for example a person who only knows the signature of one person could make sure that this person agrees that the e-mail is also sent to the the other people mentioned in the security.txt.

Describe the solution you'd like
It would be great if something along the lines of https://tools.ietf.org/html/draft-foudil-securitytxt-04#section-3.4.7 could be added again.

Additional context
I contacted the authors via email to ask about this feature. They explained to me that it was already included as part of a previous draft (link as the solution i would like to see 😉) and was removed to reduce complexity, but they suggested that I open this feature request so that it might be revisited in the future. (Thanks for the really quick and nice reply 👍)

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions

      点击 这是indexloc提供的php浏览器服务,不要输入任何密码和下载