matrix-org / matrix-org/matrix-spec
`/_matrix/key/v2/server` says it's signed by "the verify keys", but which ones from the list should be used?
Open
A-S2S
clarification
good first issue
- Dominant language
- HTML
- Stars
- 330
- Forks
- 150
- Avg merge
- 2h 21m
- Merged PRs (30d)
- 3
Description
**Link to problem area**: https://spec.matrix.org/v1.9/server-server-api/#get_matrixkeyv2server
**Issue**
I believe *all* of the `verify_keys` need to sign the object, but it's not impossible that we only require one.
Related: https://github.com/matrix-org/matrix-spec/issues/510
Contributor guide
Research direction
Start with the GET /_matrix/key/v2/server section linked in the issue, then read the related matrix-spec issue #510 for the discussion about verify_keys. Done means the specification clearly states which verify_keys must sign the object and the ambiguity in this section is resolved.
Written by the indexing model from the issue text.
Assessment
- Domain
- documentation
- Issue type
- Documentation
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 35/100