@DTS Engineer
Quick question — is the verification logic already able to verify .pkg files signed with SHA256? If not, that would mean even if Apple updates productsign to stop using NIST-disallowed algorithms, we still wouldn't be able to ship those .pkg files to users who haven't received the corresponding verification update.
Curious to hear your thoughts on this.
Topic:
Privacy & Security
SubTopic:
General
Tags: