Skip to content

How does signing actually work? #95

Answered by dennisvang
Eoic asked this question in Q&A
Discussion options

You must be logged in to vote

... When / what / how should I sign metadata files?

First let's step back a little and address "Why" you should sign metadata files

Why?

Basically, tufup downloads files from "the internet" to the computer that your app is running on, and then "installs" them.

As with anything downloaded from "the internet", there is a trust issue here: You should only run/install/use downloaded files if you trust the source.

Now, the signed metadata files are a means to establish this trust: The metadata files contain information about the "update" files that are available for download, and allows the client to verify the integrity and the authenticity of the downloaded files. The metadata files themse…

Replies: 3 comments 7 replies

Comment options

You must be logged in to vote
1 reply
@Eoic
Comment options

Answer selected by Eoic
Comment options

You must be logged in to vote
1 reply
@Eoic
Comment options

Comment options

You must be logged in to vote
5 replies
@dennisvang
Comment options

@walt-jones
Comment options

@dennisvang
Comment options

@walt-jones
Comment options

@dennisvang
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
3 participants
Converted from issue

This discussion was converted from issue #94 on December 13, 2023 13:17.