問題文
A machine expects a wrapping token whose contents come from a certificate issuing path, and the lookup succeeds but reports a creation path under the wrapping endpoint. What should the operator conclude, and why?
選択肢
- The value was probably read and wrapped again by an interceptor, because that creation path names the wrapping endpoint itself rather than the issuing path.
- The token is fine, because a lookup that succeeds proves the data has not been read.
- The creation path always names the wrapping endpoint, so it carries no information and only the remaining validity is worth checking before unwrapping.
- Comparing the first segment of the path is enough, so the operator should accept the token as long as the path begins with the certificate engine's own prefix.