include SignatureValidation filter with FileBackedHTTPMetadataProvider
Cantor, Scott
cantor.2 at osu.edu
Tue Dec 19 13:13:24 EST 2017
> If the metadata is not signed, there's no way to ensure the integrity
> of a backup file upon startup. What am I missing?
Backup files, just like files loaded explicitly by hand in the many ways supported, are presumed to be there as a result of deliberate action or previously secured source. If you don't trust your own file system, you are in deep trouble. It wouldn't have occurred to me to have to point that out but if that's what the confusion is, then that's the missing note.
Simply having the option to skip the verification of the signature, as the SP has, is the reason what you're saying isn't true from the perspective of the software. You can skip it under the presumption that the backup can only get there "safely".
-- Scott
More information about the dev
mailing list