chainloop icon indicating copy to clipboard operation
chainloop copied to clipboard

Implement keyless verification

Open jiparis opened this issue 1 year ago • 2 comments

Currently, keyless signing is in production in experimental mode, as generated attestations are not yet verifiable (because generated certificate is not stored).

This task is for implementing the full verification scenario, following best practices.

jiparis avatar Jun 06 '24 11:06 jiparis

We will adopt sigstore approach for storing and verifying local bundles.

jiparis avatar Jun 11 '24 14:06 jiparis

See https://github.com/chainloop-dev/chainloop/issues/990 for storing the verification material.

jiparis avatar Jun 19 '24 10:06 jiparis