4 ms·
Shameless plug for the gitsign project in sigstore: https://github.com/sigstore/gitsign https://github.com/sigstore/gitsign This isn't supported by GitHub yet
by dlor 4y ago
Shameless plug for the gitsign project in sigstore: https://github.com/sigstore/gitsign https://github.com/sigstore/gitsign
This isn't supported by GitHub yet but we're hopefully working towards that too.
- fariszr 4y agoIs there any other Git host/platform that supports it? Gitea/GitLab?
- sytse 4y agoIt seems on GitLab this is being working on in https://gitlab.com/gitlab-org/gitlab/-/issues/343879 https://gitlab.com/gitlab-org/gitlab/-/issues/343879 with part of the work already merged in https://gitlab.com/gitlab-org/gitlab/-/merge_requests/87962 https://gitlab.com/gitlab-org/gitlab/-/merge_requests/87962 and https://gitlab.com/gitlab-org/gitlab/-/merge_requests/88693 https://gitlab.com/gitlab-org/gitlab/-/merge_requests/88693
- fariszr 4y agoWhat about Sigstore, is there any plan on supporting it?
- wlynch 4y agoYou can find the feature request for supporting keyless sigstore/gitsign at https://gitlab.com/gitlab-org/gitlab/-/issues/364428 https://gitlab.com/gitlab-org/gitlab/-/issues/364428
- sytse 4y agoSorry, I missed the context your original question was about Sigstore. Someone answered in https://news.ycombinator.com/item?id=32569872 https://news.ycombinator.com/item?id=32569872
- wlynch 4y agoWorth calling out that gitsign works with any Git host for the commit signatures / verification! The main piece that's platform specific is the Verified badges that you see in the UI + any CI checks.
- francoispon 4y agoI think github support came out a year and half after the feature was available in git (nov 2021), so that may going to be a while :(
- LionTamer 4y agoI just looked through the website and I’m struggling to understand exactly how it works - how do you have signing / verification without the risk of key compromise?
- dwheeler 4y agoI may be misunderstanding your question, but here is the answer if I understand you correctly. This is all based on public key cryptography. In public key cryptography, there are actually 2 keys, a public key and a private key. Sites like get hub and the repose can store the public keys, while into while individual users keep their private key's secret. Anyone with the public key can verify a signature, but only an individual with the private key can create the equivalent signature. The trick is to determine if a given public key corresponds to an individual. There are various methods to try to address that. I hope that helps!
- Foxboron 4y agoThe same way LetsEncrypt makes compromised TLS certificates (almost) useless; short-lived certificats. What the sigstore project does is having an oauth portal which can authenticate one of your online identities. It uses this to sign a temporary certificate for you with it's root CA. This certificate is what you use to sign commits and artifacts with.
- wlynch 4y ago+1 to this! https://docs.sigstore.dev/fulcio/certificate-issuing-overview https://docs.sigstore.dev/fulcio/certificate-issuing-overvie... has a good overview of how the certificate issuing works. With Gitsign, by default a new keypair is generated per signing event (i.e. per commit) and never hits disk. The cert in the commit signature holds the public key, which we can check against Rekor (https://docs.sigstore.dev/rekor/overview https://docs.sigstore.dev/rekor/overview) to verify it was valid at the time of signing. If you have the time, https://www.youtube.com/watch?v=PVhRQFS9Njg https://www.youtube.com/watch?v=PVhRQFS9Njg is a great deep dive into how Sigstore works in general!
- deleted 4y ago[deleted]
- 616c 4y agoSuper excited and can't wait!