You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Per the storage section of the signature specification, the annotation io.cncf.notary.x509chain.thumbprint#S256 is "A REQUIRED annotation whose value contains the list of SHA-256 fingerprint of signing certificate and certificate chain (including root) used for signature generation."
I wanted to understand if the annotation io.cncf.notary.x509chain.thumbprint#S256 is still required, as I have been able to attach an artifact without this annotation and then later verify using notation v1.0.0-rc.2.
In this scenario, the annotation appears to be optional which aligns with this earlier signature spec which includes the following for the annotation: "This OPTIONAL property contains arbitrary metadata for the image manifest."
Also, it would be helpful to understand if the annotation io.cncf.notary.x509chain.thumbprint#S256 is required (e.g. as of a certain released notation version), or if it's required for the future
The text was updated successfully, but these errors were encountered:
Per the storage section of the signature specification, the annotation io.cncf.notary.x509chain.thumbprint#S256 is "A REQUIRED annotation whose value contains the list of SHA-256 fingerprint of signing certificate and certificate chain (including root) used for signature generation."
I wanted to understand if the annotation io.cncf.notary.x509chain.thumbprint#S256 is still required, as I have been able to attach an artifact without this annotation and then later verify using notation v1.0.0-rc.2.
The text was updated successfully, but these errors were encountered: