Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-63647

Add a cosign signing key to redhat-release to enable container verification

Linking RHIVOS CVEs to...Migration: Automation ...SWIFT: POC ConversionSync from "Extern...XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Done-Errata
    • Icon: Major Major
    • rhel-10.0
    • rhel-10.0
    • redhat-release
    • None
    • redhat-release-10.0-20.el10
    • No
    • Low
    • rhel-emerging
    • 10
    • None
    • QE ack, Dev ack
    • False
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • None

      RHEL Containers on Konflux plan to introduce a new signing method in addition to traditional gpg signing for images published to registry.redhat.io and registry.access.redhat.com

      A new signing key was generated for this service and passed review in SIGNSERVER-1394

      To allow for verification on installed RHEL machines, we need to ship the public key component in redhat-release so that the container stack can include it in its policy.

      This is currently scoped only to RHEL 10.0 GA, other releases may or may not introduce cosign validation at a later time.

              bstinson@redhat.com Brian Stinson
              bstinson@redhat.com Brian Stinson
              Troy Dawson Troy Dawson
              Release Test Team Release Test Team
              Votes:
              0 Vote for this issue
              Watchers:
              7 Start watching this issue

                Created:
                Updated:
                Resolved: