Skip to content

Does each of the root metadata roles require at least one keyid, and a threshold >= 1? #251

Description

@erickt

In the root.json part of the spec, it states that it is required to have a role defined for root, targets, snapshot, timestamp, and optionally mirror. However in the section for keyid, it does not explicitly state that each role needs to have at least one keyid. Should it? Presumably we should, otherwise we would allow for unsigned metadata.

Likewise, should we also require that threshold must be greater than or equal to one?

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions