On 30 April 2010 19:39, Martin Langhoff <martin.langh...@gmail.com> wrote: > Fair enough. One of the problems is that normally the expiry check is > done inside bitfrost lib and the code there only respects the system > clock. > > So it's a bit messy. Rework bitfrost libs (with impact on users if the > lib) or implement a bit of code that knows enough about the sig format > to find out all the expiry dates and picks the lowest one... > > If you really want it, I'll try find the time, though it's... messy.
It seems like a pretty important security hole to me. We should do this stuff properly. Daniel _______________________________________________ Devel mailing list Devel@lists.laptop.org http://lists.laptop.org/listinfo/devel