feat(crypto): CRP-1857 set timestamps in pubkey store on key generation #8415
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Sets the key generation timestamp in the public key store for the node signing key, the committee signing key, and the NI-DKG dealing encryption key. So far, this was only done for the iDKG dealing encryption key (because it was needed for key rotation).
This PR does not set the key generation timestamp for the node's TLS certificate, because it uses a different protobuf message (
X509PublicKeyCert) that currently doesn't have a timestamp field. Rather than adding a timestamp field to this protobuf message, the TLS certificate can and should be migrated away from using theX509PublicKeyCertprotobuf message to also using thePublicKeyprotobuf message, which is used used by all other public keys.