Artifact Signing & Sigstore
Signing binds a trusted identity to exact bytes, and keyless flows have replaced long-lived release keys. Interviewers probe the chain: OIDC identity, short-lived certificate, transparency log.
on this pageshowhide
explore
- What Signatures Prove11 questions
- Signatures Versus Digests3 questions
- Key Custody Problem4 questions
- Whose Signature You Accept4 questions
- Keyless Identity Chain12 questions
- Signing With Cosign4 questions
- Fulcio Identity Certificates4 questions
- Rekor Transparency Log4 questions
- Ecosystem Trust Material8 questions
- GPG Release Signing4 questions
- Publish-Time Attestations4 questions
questions
page 2 of 2How do you stop your set of accepted signing identities from becoming an unreviewable allowlist?
level: principalimportance: nice to knowfreq 28%
basics
~20 sGive every accepted identity an owner, a justification, a scope and an expiry, then reconcile the list against what has actually signed anything recently. Additions are always urgent and removals never are, so the set ratchets unless expiry is the default.
showing 31–31 of 31