Uploaded image for project: 'OpenShift Request For Enhancement'
  1. OpenShift Request For Enhancement
  2. RFE-5444

Cosign Signature verification at runtime time with cosign BYOPKI

XMLWordPrintable

    • Icon: Feature Request Feature Request
    • Resolution: Done
    • Icon: Undefined Undefined
    • None
    • None
    • None
    • None
    • False
    • None
    • False
    • Not Selected

      As a customer, I am signing my images using BYOPKI Cosign, one of the options supported by Cosign. 

      Use case as described by the customer: Customer signs the artifact using unique pair of keys in their own PKI, and use cosign to attach the generated signature and certificate, certificate chain in Registry. OpenShift must be able to verify the artifact by passing trusted root certificate at runtime.

            gausingh@redhat.com Gaurav Singh
            rh-ee-masimonm Maria Simon Marcos
            Votes:
            0 Vote for this issue
            Watchers:
            7 Start watching this issue

              Created:
              Updated:
              Resolved: