Uploaded image for project: 'OpenShift Request For Enhancement'
  1. OpenShift Request For Enhancement
  2. RFE-5444

Cosign Signature verification at runtime time with cosign BYOPKI

XMLWordPrintable

    • Icon: Feature Request Feature Request
    • Resolution: Done
    • Icon: Undefined Undefined
    • None
    • None
    • None
    • None
    • False
    • None
    • False
    • Not Selected

      As a customer, I am signing my images using BYOPKI Cosign, one of the options supported by Cosign. 

      Use case as described by the customer: Customer signs the artifact using unique pair of keys in their own PKI, and use cosign to attach the generated signature and certificate, certificate chain in Registry. OpenShift must be able to verify the artifact by passing trusted root certificate at runtime.

              gausingh@redhat.com Gaurav Singh
              rh-ee-masimonm Maria Simon Marcos
              Votes:
              0 Vote for this issue
              Watchers:
              8 Start watching this issue

                Created:
                Updated:
                Resolved: