Skip to content

Conflicting signature keyid uniqueness requirements #308

@lukpueh

Description

@lukpueh

This paragraph from the metadata format section ...

The keyid MUST be unique in the "signatures" array: multiple
signatures with the same keyid are not allowed.

... seems to conflict with these paragraphs from the metadata format section ...

Note: The "signatures" list SHOULD only contain one SIGNATURE per
KEYID. This helps prevent multiple signatures by the same key

... and the client workflow section ...

Even if a KEYID is listed more than once in the
"signatures" list a client MUST NOT count more than one verified
SIGNATURE from that KEYID towards the THRESHOLD.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions