Skip to content

Keyless signing #865

@jiparis

Description

@jiparis

The goal of this task is to provide a first glipse of keyless signing using a file-based certificate authority to sign certificate requests from the CLI. KMS will come later, but in this issue we want to prioritize the experience and explore the different use cases for Chainloop.

The proposed workflow is:

  1. user does an attestation push without providing a key
  2. the CLI generates a CSR and sends it to Chainloop
  3. Chainloop signs the CSR and returns a full certificate chain for signing
  4. the CLI signs the attestation and creates a DSSE envelope as usual

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions