Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add a notice about verification of keyless signing #1472

Merged
merged 1 commit into from
Aug 4, 2022

Conversation

wata727
Copy link
Member

@wata727 wata727 commented Aug 4, 2022

Verification by Cosign is not perfect. Currently, the cosign verify-blob command does not verify the certificate chain against the Fulcio root trust, so the attacker can replace checksum.txt, checksum.txt.keyless.sig, and checksum.txt.pem.

This way is the same as distributing a different public key for each release and having users download it. That is, verifiers must find a way to safely get checksum.txt.pem (in a different way than checksum.txt).

@wata727 wata727 merged commit e7668cb into master Aug 4, 2022
@wata727 wata727 deleted the add_notice_about_keyless_signing branch August 4, 2022 17:32
wata727 added a commit that referenced this pull request Aug 20, 2022
wata727 added a commit that referenced this pull request Aug 20, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

Successfully merging this pull request may close these issues.

1 participant