Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Long-running process will not fetch updated Fulcio certificates #1600

Open
haydentherapper opened this issue Jan 16, 2024 · 0 comments
Open
Labels
bug Something isn't working

Comments

@haydentherapper
Copy link
Contributor

initRoots initializes a TUF environment and will update the target metadata if expired. The results of initRoots are persisted in a singleton to prevent repeated lookups of the certificates from the local TUF repo. The issue is that the TUF metadata may expire, but the singleton will prevent fetching the potentially-updated Fulcio roots.

I'd propose removing the singleton and always read from the TUF metadata. Alternatively the TUF client could persist the certificates and update its copy when the TUF metadata expires.

@haydentherapper haydentherapper added the bug Something isn't working label Jan 16, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

1 participant