Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

SPKAC can be instantiated with challenge=None and somehow yield usable client certs #7

Open
phryk opened this issue Aug 21, 2017 · 0 comments

Comments

@phryk
Copy link

phryk commented Aug 21, 2017

Okay, so I'm not sure what exactly I'm trying to accomplish with this issue.

<keygen> is sadly dying and this project seems pretty dead, too.

But if you somehow stumbled into maintaining something using this thing, take care to make sure you're not passing None for the challenge parameter as I'm pretty sure this has security implications (vulnerable to replay attacks, maybe?).
Mostly I'm just confused why this even yields usable certificates…

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant