You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Currently the notary reply does not contain the host name. We should include it so clients can verify that the fingerprint returned is indeed for the host they expected.
Using SSL to encrypt the reply would also protect against attacks, but we should include it in the reply just in case.
The text was updated successfully, but these errors were encountered:
Dave, the signature on the reply include the service_id, which includes the hostname + port, so there is no risk of the reply being for a different host and still being accepted by the client.
Currently the notary reply does not contain the host name. We should include it so clients can verify that the fingerprint returned is indeed for the host they expected.
Using SSL to encrypt the reply would also protect against attacks, but we should include it in the reply just in case.
The text was updated successfully, but these errors were encountered: