Skip to content

TSA verification only works for sha256 #1375

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
jku opened this issue May 9, 2025 · 0 comments · Fixed by #1385
Closed

TSA verification only works for sha256 #1375

jku opened this issue May 9, 2025 · 0 comments · Fixed by #1385
Labels
enhancement New feature or request

Comments

@jku
Copy link
Member

jku commented May 9, 2025

Verifier assumes the timestamp hash algorithm is SHA256 but this is not necessarily the case.

trailofbits/rfc3161-client#144 should make it fairly easy to verify using the correct hash algorithm.

See also #1372

@jku jku added the enhancement New feature or request label May 9, 2025
@jku jku linked a pull request May 21, 2025 that will close this issue
@jku jku closed this as completed in #1385 May 27, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant