• Icon: Sub-task Sub-task
    • Resolution: Done
    • Icon: Undefined Undefined
    • None
    • None
    • None
    • None
    • False
    • False
    • OCPSTRAT-438 - Support Creation for DISA-STIG Profile
    • CMP Sprint 41

          [CMP-1174] SRG-APP-000131-CTR-000285: OCP must verify container images

          Vincent Shen added a comment - - edited

          Thanks for taking a look on this, we have a rule to check if the policy is in place: https://github.com/ComplianceAsCode/content/blob/master/applications/openshift/integrity/reject_unsigned_images_by_default/rule.yml, I copied the check to the spreadsheet

          Vincent Shen added a comment - - edited Thanks for taking a look on this, we have a rule to check if the policy is in place: https://github.com/ComplianceAsCode/content/blob/master/applications/openshift/integrity/reject_unsigned_images_by_default/rule.yml, I copied the check to the spreadsheet

          Dusty Mabe added a comment - - edited

          Following the breadcrumbs from #1349 it appears that all images are signed now. Most everything in this space is linking to https://access.redhat.com/verify-images-ocp4 for how to do it.

          Dusty Mabe added a comment - - edited Following the breadcrumbs from #1349 it appears that all images are signed now . Most everything in this space is linking to https://access.redhat.com/verify-images-ocp4 for how to do it.

          Colin Walters added a comment - https://github.com/openshift/machine-config-operator/issues/1349

          Colin Walters added a comment - Related: https://github.com/openshift/machine-config-operator/pull/803

          Dusty Mabe added a comment -

          Dusty Mabe added a comment - Link to the cell in the spreadsheet: https://docs.google.com/spreadsheets/d/1oTUEUSkpumEpGqeBvhEHkJxcGUxMgoG1/edit#gid=959715005&range=C45

            wenshen@redhat.com Vincent Shen
            daanders@redhat.com David Anderson
            Votes:
            0 Vote for this issue
            Watchers:
            5 Start watching this issue

              Created:
              Updated:
              Resolved: