tree 51d0ac022472c753959e0c86faeaabba5a527069
parent 0d40b25637fa35e4e546a0bafebaa7ee4591e172
author Zack Newman <z@znewman.net> 1662564882 -0400
committer GitHub <noreply@github.com> 1662564882 -0400
gpgsig -----BEGIN PGP SIGNATURE-----
 
 wsBcBAABCAAQBQJjGLoSCRBK7hj4Ov3rIwAAPOUIAKnLbXjLe0y1fFeADB0z8bb0
 Mrm+3Mw+xcbB7oVvUN9av7CwerTUnkR9tRNw0nT2ypSFvEtst3HJnMRZVENS4Snu
 vpG347DcutfzmMxtwXD07dXfZWhOx/PIVH+Xa2vG9jWZYS6j/42Bdpa8ygqFI0oA
 Zt+u7JjGWU1wvcYlhWwy5kIlY59C3UDr930W6ZsRtegL4Jbb6aVM/3crmQtuzNBc
 N21DejELfXCgmpcgDpLCbyuMnYAH7mtUEOYNEkh/u+Pgs8ZytvEOWJZ5GFdjZUDh
 Y223F0YGPGaTEHFo0UVaTBQxdhn+vGyVEUr0RvlDTjhjt4ig0vsYeVBrB9JXqBA=
 =ruHT
 -----END PGP SIGNATURE-----
 

fix(verify): backport "Fix a vulnerability in the verification of threshold si… (#375)

fix(verify):  Fix a vulnerability in the verification of threshold signatures (due to handling of keys with multiple IDs) (#369)

* add test for several signatures same key diff ID

* fix verifying threshold signatures

* add some comments

* rename variables and add comments

Co-authored-by: Trishank Karthik Kuppusamy <trishank.kuppusamy@datadoghq.com>
Signed-off-by: Zachary Newman <z@znewman.net>

Signed-off-by: Zachary Newman <z@znewman.net>
Co-authored-by: Cédric Van Rompay <97546950+cedricvanrompay-datadog@users.noreply.github.com>
Co-authored-by: Trishank Karthik Kuppusamy <trishank.kuppusamy@datadoghq.com>