oxidecomputer / oxidecomputer/lpc55_support

DCSR signing

Open
#91 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Rust
Stars
13
Forks
7
PR merge metrics
No merged PRs in 30d

Description

DCSRs are an analog to CSRs but we're not signing them. CSRs are signed by the originator to ensure their integrity can be verified at the destination (some layer in the PKI). We should be doing the same w/ DCSRs when we generate them.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by locating the code that generates DCSRs and compare it with the existing CSR generation and signing path. Trace how the destination verifies CSR integrity, then determine the corresponding DCSR signing entry point. Done means newly generated DCSRs carry a signature that can be verified at the destination.

Written by the indexing model from the issue text.

Assessment

Tech stack
rust
Domain
cryptography, security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.