Skip to content

Clarify root role update wording #311

Closed
@udf2457

Description

@udf2457

As presently documented, 5.3.11 is somewhat unclear.

It states:

If the timestamp and / or snapshot keys have been rotated, then delete the trusted timestamp and snapshot metadata files.

But this raises the question of what trusted timestamp and snapshot metadata files ?

The first time "trusted timestamp" or "trusted snapshot" are mentioned in the Spec is later in the document.

So it is therefore unclear on what happens on Day-0 ? i.e. A new client with nothing other than a bundled trusted root.

Is 5.3.11 not applicable in Day-0 scenarios ? Or are we supposed to monitor for such rotations during Day-0 initialisation and bubble up an error or abort ?

(Potentially vaguely related to #240 and/or #235 and/or #186 and/or #71)

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions