cosign icon indicating copy to clipboard operation
cosign copied to clipboard

Add support for multiple PIV tokens

Open almet opened this issue 2 months ago • 1 comments

Right now, Cosign doesn't allow to sign when multiple PIV tokens are connected: it errors out and no signatures re generated:

signing digest: getting keypair and token: getting signer: open key: found 2 cards, please attach only one

This can be problematic in scenarios where you are using a machine in which you don't have physical access.

Having a way to filter the PIV tokens by specifying a --piv-uuid flag would be a way to solve this.

What do you think? Would such a contribution welcome?

almet avatar Oct 24 '25 10:10 almet

Would such a contribution welcome?

That sounds useful!

cmurphy avatar Oct 28 '25 18:10 cmurphy