You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The tuf/in-toto signature metadata format specification treats the exact signature format as implementation detail. The (tuf spec) only says that the signature field contains a:
A hex-encoded signature of the canonical form of the metadata for
For the sake of interoperability -- i.e. 3rd-party signature verification or generation of signatures generated by or to be verified by securesystemslib -- the Signer API should document the exact signature format per signing scheme, e.g. for
"ecdsa-sha2-nistp256" and "ecdsa-sha2-nistp384":
Note that the documentation should be available per scheme and not per signer, because securesystemslib may implement different signers that generate signatures for the same schemes. E.g. ecdsa signatures can be generated on HSM and in memory.
The text was updated successfully, but these errors were encountered:
The tuf/in-toto signature metadata format specification treats the exact signature format as implementation detail. The (tuf spec) only says that the signature field contains a:
For the sake of interoperability -- i.e. 3rd-party signature verification or generation of signatures generated by or to be verified by securesystemslib -- the Signer API should document the exact signature format per signing scheme, e.g. for
"ecdsa-sha2-nistp256" and "ecdsa-sha2-nistp384":
Note that the documentation should be available per scheme and not per signer, because securesystemslib may implement different signers that generate signatures for the same schemes. E.g. ecdsa signatures can be generated on HSM and in memory.
The text was updated successfully, but these errors were encountered: