theupdateframework / theupdateframework/theupdateframework.io
Clarity needed in relation to Snapshot role and online vs offline
Nobody has claimed this yet.
- Dominant language
- HTML
- Stars
- 25
- Forks
- 46
- PR merge metrics
- No merged PRs in 30d
Description
At the moment, the website can't seem to make its mind up as to whether Snapshot role keys should be online or offline.
Really someone needs to decide once and for all and stick to it, instead of all this conflicting wording.
If we consider the Specification as the ultimate source of truth, then we are told:
All keys, except those for the timestamp and mirrors roles, should be stored securely offline
content/metadata.md seems to agree:
so that the Snapshot role's keys can be kept offline, and thus more secure
So far so good. But the FAQ content/faq.md is where you have the bouncing around. On one page we are told two different things...
Three places state online:
even sharing online keys (e.g., between the Timestamp and Snapshot roles)
In contrast, the Snapshot role is updated often, signed with an online key
The Timestamp and Snapshot roles can use online keys
And then we have a suggestion of offline for Snapshot:
separate keys should be used so that the Snapshot role’s keys can be kept offline, and thus in a more secure manner.
If we assume the Specification reflects the TUF design decision, then the rest of the website should be consistent.
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Compare the Snapshot key guidance in content/metadata.md and content/faq.md with the Specification cited in the issue. First establish which guidance is authoritative, then update the conflicting website wording so the references agree. Done means the FAQ and metadata documentation consistently describe Snapshot role key storage.
Written by the indexing model from the issue text.
Assessment
- Domain
- documentation
- Issue type
- Documentation
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100