Skip to content

Cleartext: Only allow valid hashes in header#298

Merged
lubux merged 3 commits intomainfrom
feat/cleartext-hash-header
Jan 7, 2026
Merged

Cleartext: Only allow valid hashes in header#298
lubux merged 3 commits intomainfrom
feat/cleartext-hash-header

Conversation

@lubux
Copy link
Copy Markdown
Member

@lubux lubux commented Jan 7, 2026

According to RFC9580 a verifying application MUST decline to validate
any signature in a message with a non-conformant Hash header.

This got lost in the v2 update.

According to RFC9580 a verifying application MUST decline to validate
any signature in a message with a non-conformant Hash header.
@lubux lubux force-pushed the feat/cleartext-hash-header branch from 3ec9cfa to cfb2af9 Compare January 7, 2026 16:28
@lubux lubux merged commit a8cc4f0 into main Jan 7, 2026
9 checks passed
@lubux lubux deleted the feat/cleartext-hash-header branch January 7, 2026 16:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants