Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Allow everyone to publish to transparency log #7

Closed
mahdi-ln opened this issue Oct 23, 2021 · 1 comment
Closed

Allow everyone to publish to transparency log #7

mahdi-ln opened this issue Oct 23, 2021 · 1 comment

Comments

@mahdi-ln
Copy link

mahdi-ln commented Oct 23, 2021

A client receives a package that is signed by Arch. Why shouldn't it can publish package data (including publisher signature) to public log? Why you should wait until the package's publisher or Arch, do that?
This way we have a more decentralized audition, too

@kpcyrd
Copy link
Owner

kpcyrd commented Oct 23, 2021

hi,

Arch packages are signed using pgp keys which are generally multi-purpose. For binary transparency to be effective you need a complete view of all signed data, this is why additional signatures are created.

You could in theory create these signatures yourself by deploying pacman-bintrans-sign yourself.

The transparency signatures can be submitted to rekor.sigstore.dev by anyone, but the pacman-bintrans client is currently just rejecting them instead if they aren't already included in the log.

@kpcyrd kpcyrd closed this as completed Oct 23, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants