Admin message

Due to an influx of spam, we have had to temporarily disable account registrations. Please write an email to accountsupport@archlinux.org, with your desired username, if you want to get access. Sorry for the inconvenience.

Open
Milestone

Security audit

Before production deployment of the Signstar system, ideally an audit by third-party security researchers should take place.

Such an audit should encompass gray-box testing of the entire hardware test system and its update mechanism, as well as a code audit of the Signstar code base. Security audits should be carried out by professional security labs with a public track record and an established understanding of the underlying technology and involved programming languages.

As the costs of such an audit are estimated at over €100.000, a sponsored code audit should be applied for. A missing audit should not circumvent deployment, but instead be sought after in the future.

  • Work items 0
  • Merge requests 0
  • Participants 0
  • Labels 0
Loading
Loading
Loading
Loading
0% complete
0%
Start date
No start date
None
Due date
No due date
0
Work items 0 New issue
Open: 0 Closed: 0
None
Total weight
None
0
Merge requests 0
Open: 0 Closed: 0 Merged: 0
0
Releases
None
Reference: archlinux/signstar%"Security audit"