What is Nostr?
Matthew Garrett /
npub1aa0…ejrs
2024-08-14 05:05:50
in reply to nevent1q…lgy5

Matthew Garrett on Nostr: Why do you care that the certs are fresh? If you encode group membership in certs you ...

Why do you care that the certs are fresh? If you encode group membership in certs you want to have an upper bound on how long someone can continue to access a resource after being removed from a group. The TPM clock is monotonic based on the TPM being powered, so you can just subtract the attestation time from the current TPM time and get an upper bound on how long ago the cert was issued.
Author Public Key
npub1aa0gpek8gwr77984c6ufq70j9d5y0hq5xegqrs8dvc4zp0vfzemsuuejrs