Post

Replies

Boosts

Views

Activity

Comment on App Store Notifications v2 - Verifying a signature
Thanks for the summary @hoelska , really helpful. As noted by @Elephant Head Software, looking at the implementation of the official library we can find a comment indicating that "We don't include the root cert in the path, due to OCSP not being supported", also the code discards the root (3rd) certificate. If I get it correctly it means that there is not point to check for online revocation ?
Feb ’24