5 ms·
The same way LetsEncrypt makes compromised TLS certificates (almost) useless; short-lived certificats. What the sigstore project does is having an oauth portal
by Foxboron 4y ago
The same way LetsEncrypt makes compromised TLS certificates (almost) useless; short-lived certificats.
What the sigstore project does is having an oauth portal which can authenticate one of your online identities. It uses this to sign a temporary certificate for you with it's root CA. This certificate is what you use to sign commits and artifacts with.
- wlynch 4y ago+1 to this! https://docs.sigstore.dev/fulcio/certificate-issuing-overview https://docs.sigstore.dev/fulcio/certificate-issuing-overvie... has a good overview of how the certificate issuing works. With Gitsign, by default a new keypair is generated per signing event (i.e. per commit) and never hits disk. The cert in the commit signature holds the public key, which we can check against Rekor (https://docs.sigstore.dev/rekor/overview https://docs.sigstore.dev/rekor/overview) to verify it was valid at the time of signing. If you have the time, https://www.youtube.com/watch?v=PVhRQFS9Njg https://www.youtube.com/watch?v=PVhRQFS9Njg is a great deep dive into how Sigstore works in general!
- deleted 4y ago[deleted]