https://bugzilla.mindrot.org/show_bug.cgi?id=3516

--- Comment #6 from William Brown <[email protected]> ---
(In reply to Damien Miller from comment #5)
> > This doesn't help when the challenge *isn't* specified though,
> > meaning that if attestation is requested
> 
> Attestation without a verifier-specified challenge is pretty
> worthless, as otherwise there is no guarantee of freshness, or
> conversely, it would allow replay of prior attestations.

Then when attestation is requested, it should be an error to also not
provide a challenge parameter.

-- 
You are receiving this mail because:
You are watching the assignee of the bug.
You are watching someone on the CC list of the bug.
_______________________________________________
openssh-bugs mailing list
[email protected]
https://lists.mindrot.org/mailman/listinfo/openssh-bugs

Reply via email to