Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-33556

[RHEL EPIC] Adopting Sigstore for Containers - RHEL 10.0 Beta

    • [RHEL EPIC] Adopting Sigstore for Containers - RHEL 9.5
    • Hide

      The following needs to be verified in order for this epic to be considered complete:

      • Testing as specified by the SME is sufficient.
      Show
      The following needs to be verified in order for this epic to be considered complete: Testing as specified by the SME is sufficient.
    • Red Hat Enterprise Linux
    • sst_container_tools
    • False
    • Hide

      None

      Show
      None
    • Dev ack

      Epic Description

      Begin using Sigstore signatures for container signing in RHEL / UBI.

      Detailed Sigstore rationale and background here.

      There is no work here for the Development Team, this is mostly work for packaging, and possible work for QE and Documentation.

      SME: Miloslav Trmac

      Goals

      Adopting sigstore for signing RHEL/UBI based containers provides a more ergonomic experience for users and is in line with wider container-signing plans.

      RHEL/UBI 7/8/9 will continue to have simple-signatures. RHEL 10 images would be sigstore only.

      Note: simple-signing code will not be removed from RHEL container tools, so any user re-signing workflows will continue to function.

      Requirements

      All supported versions of RHEL container tools in RHEL and in layered products must have the code paths and correctly configured policy in order to use UBI10 containers from RHEL9 based systems.

       

      (Optional) Use Cases
      Out of Scope

       

      Background, and strategic fit

      Assumptions

      Customer Considerations

      Documentation Considerations

      Interoperability Considerations

       

      Questions

      Question Outcome
         

       

            tsweeney@redhat.com Tom Sweeney
            tsweeney@redhat.com Tom Sweeney
            Container Runtime Eng Bot Container Runtime Eng Bot
            Container Runtime Bugs Bot Container Runtime Bugs Bot
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated:
              Resolved: