logoalt Hacker News

glitchcyesterday at 7:50 PM1 replyview on HN

You're clearly not using these keys in certificates, which would need to be signed by a root or interim CA on every update.


Replies

bob1029yesterday at 8:07 PM

Correct. The keys are only used for signing JWTs. Trust was established with the vendor out of band from this wire protocol (the URL they scan for public keys).

show 1 reply