in-toto / attestation

in-toto Attestation Framework

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Add guidance on how & how not to verify attestations

TomHennen opened this issue · comments

Probably

  1. Not all fields necessary need to be verified (some are just for 'debugging' information)
  2. Reconstruction is not viable, clients won't know the values of all fields.

Anything else?

It occurs to me that the Parsing rules would seem to do this already?

Independent reconstruction would seem to be incompatible with the requirement to ignore unrecognized fields?

This may or may not be related to #290 .