You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Hi. It seems 'cosign sign' supports on-disk private keys and PKCS#11 tokens, PIV cards, AWS KMS, GCP KMS, Azure Key Vault, Hashicorp Vault. But there is one fairly common way to access private-keys that is missing: through a SSH agent socket.
Am I missing anything, or is support for signing via a SSH agent socket missing from cosign?
If so, please consider this a request to add support for it.
There is a bunch of SSH agents providing access to private keys held on OpenPGP cards, TPMs, etc that would then be accessible for use by Sigstore cosign.
Thanks,
/Simon
The text was updated successfully, but these errors were encountered:
Hi. It seems 'cosign sign' supports on-disk private keys and PKCS#11 tokens, PIV cards, AWS KMS, GCP KMS, Azure Key Vault, Hashicorp Vault. But there is one fairly common way to access private-keys that is missing: through a SSH agent socket.
Am I missing anything, or is support for signing via a SSH agent socket missing from cosign?
If so, please consider this a request to add support for it.
There is a bunch of SSH agents providing access to private keys held on OpenPGP cards, TPMs, etc that would then be accessible for use by Sigstore cosign.
Thanks,
/Simon
The text was updated successfully, but these errors were encountered: