Skip to content

Commit

Permalink
attempt to unblock ipr checking status
Browse files Browse the repository at this point in the history
  • Loading branch information
riccardoAlbertoni authored Aug 6, 2023
1 parent 466aa45 commit c45f14d
Showing 1 changed file with 1 addition and 1 deletion.
2 changes: 1 addition & 1 deletion dcat/index.html
Original file line number Diff line number Diff line change
Expand Up @@ -5984,7 +5984,7 @@ <h2>Security and Privacy Considerations</h2>
</p>
<p>Some datasets require assurances of integrity and authenticity (for example, data about software vulnerabilities). For these, checksums can serve as a type of verification.
DCAT borrows the <a href="#Class:Checksum"><code>spdx:Checksum</code></a> class from [[!SPDX]] to ensure the integrity and authenticity of DCAT distributions. Publishers may provide a checksum value (a hash) and the algorithm used to generate the hash for each resource in the distribution. A checksum must, however, be provided via a route that is separate from the data it sums. It may be included in metadata that is provided with the data (e.g., a tarfile that includes a file for the distribution and a file for the metadata that includes a checksum for the distribution file), but if so the checksum, or a checksum for the metadata, must also be provided separately to foil an attacker who would manipulate the checksum along with the data. A checksum provided in DCAT metadata will not provide the expected assurances if the integrity and authenticity of the metadata are not also guaranteed.
</p>
</p>
<p>Integrity and authenticity of DCAT data ultimately depend on the trustworthiness of the source. DCAT providers should address integrity and authenticity at the application level and transport level. For example, they should ensure the integrity and authenticity of their API and download endpoints, make DCAT data and metadata files downloadable from authoritative HTTPS origins, and provide any checksums via a separate channel from the data they represent.
</p>
</section>
Expand Down

0 comments on commit c45f14d

Please sign in to comment.