Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

detached signatures (allow multiple people to sign the security.txt) #206

Open
herbetom opened this issue Mar 18, 2021 · 0 comments
Open

Comments

@herbetom
Copy link

Is your feature request related to a problem? Please describe.
It would be really helpfull if more then one signature could be used to verfify the content of the security.txt

For smaller projects you might not want to go through the effort of managing a common address and a common gpg key, but just list the email addresses of several people involved in the project as Contact. Under Encryption you link the appropriate public keys and you have a security.txt relatively quickly.

But now it would be nice if more than one person could sign the security.txt and it would not be limited to one signature. So for example a person who only knows the signature of one person could make sure that this person agrees that the e-mail is also sent to the the other people mentioned in the security.txt.

Describe the solution you'd like
It would be great if something along the lines of https://tools.ietf.org/html/draft-foudil-securitytxt-04#section-3.4.7 could be added again.

Additional context
I contacted the authors via email to ask about this feature. They explained to me that it was already included as part of a previous draft (link as the solution i would like to see 😉) and was removed to reduce complexity, but they suggested that I open this feature request so that it might be revisited in the future. (Thanks for the really quick and nice reply 👍)

@herbetom herbetom changed the title detached signatures detached signatures (allow multiple people to sign the security.txt) Mar 18, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants