include SignatureValidation filter with FileBackedHTTPMetadataProvider

Tom Scavo trscavo at gmail.com
Tue Dec 19 13:03:05 EST 2017


On Tue, Dec 19, 2017 at 12:57 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:
>> If the metadata is NOT signed, do not use FileBackedHTTPMetadataProvider.
>>
>> Why? Because if you do, there's no security upon startup.
>
> Except that is *not* true.

If the metadata is not signed, there's no way to ensure the integrity
of a backup file upon startup. What am I missing?

Tom


More information about the dev mailing list