Skip to content

Conversation

@cmurphy
Copy link
Contributor

@cmurphy cmurphy commented Jan 16, 2026

If an SCT includes an extension, its signature is signed over the entire data structure including the extension.

Followup to #1657
Relates to sigstore/rekor-tiles#73
Fixes conformance failure in https://github.com/sigstore/sigstore-conformance/actions/runs/21049488308/job/60532184810?pr=319

Summary

Release Note

Documentation

If an SCT includes an extension, its signature is signed over the entire
data structure including the extension.

Signed-off-by: Colleen Murphy <[email protected]>
@woodruffw
Copy link
Member

/gcbrun

Copy link
Member

@woodruffw woodruffw left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks @cmurphy! The conformance test is good enough for merge here IMO, but it'd be great to also have a unit test in tree for this (I think we have other tests for SCTs that lack these extension bytes.)

@woodruffw woodruffw merged commit e6cc009 into sigstore:main Jan 16, 2026
41 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants