Skip to content
This repository has been archived by the owner on Feb 12, 2022. It is now read-only.

Verify pgp signature with "certificate-pinning" #18

Open
k3b opened this issue Jul 1, 2016 · 0 comments
Open

Verify pgp signature with "certificate-pinning" #18

k3b opened this issue Jul 1, 2016 · 0 comments

Comments

@k3b
Copy link

k3b commented Jul 1, 2016

Is it possible to implement a verification system that garantees that the pgp-signatures (*.asc files) are still correct and that the pgp-signer is still the same?

The current implementation of gradle-witness verifies that the checksum of the lib is correct.

As a developer every time i whish to use a new lib version i have to update the checksum, too.

With the pinned-pgp-signer verification i can declare trust in the signer. there is no need to update the signature in the gralde file when there are version updates. update is only neccessary if the pgp-signer changes

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Development

No branches or pull requests

1 participant