Move prior PCR management into QLDB #2502
Labels
nitro-payments
spec needed
a specification is needed before development can begin because this change would not be contained
I propose that to improve usability and reduce the chances of PCR updates being forgotten, we look into migrating the prior PCR list to QLDB. It could for instance be signed by a vault derived key in order to authenticate it's providence as a PCR which we completed bootstrap for.
@Sneagan notes that we could do this at time of first prepare/authorize rather than at bootstrap time.
cc @kdenhartog
The text was updated successfully, but these errors were encountered: