From 85b5b0001893aaa4c79735ffb336159ef49a1814 Mon Sep 17 00:00:00 2001 From: Michal Fojtik Date: Wed, 25 Jan 2017 15:36:34 +0100 Subject: [PATCH] verify identity against user input --- pkg/cmd/admin/image/verify-signature.go | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/pkg/cmd/admin/image/verify-signature.go b/pkg/cmd/admin/image/verify-signature.go index 1d5dc05981cb..f742a10f3184 100644 --- a/pkg/cmd/admin/image/verify-signature.go +++ b/pkg/cmd/admin/image/verify-signature.go @@ -151,7 +151,6 @@ func (o *VerifyImageSignatureOptions) verifySignatureContent(content []byte) (st if o.InputImage != m.Critical.Image.Digest { return "", "", fmt.Errorf("signature is valid for digest %q not for %q", m.Critical.Image.Digest, o.InputImage) } - fmt.Printf("critical=%#+v\n", m.Critical) return m.Critical.Image.Digest, m.Critical.Identity.DockerReference, nil } @@ -168,7 +167,7 @@ func (o *VerifyImageSignatureOptions) verifyImageIdentity(reference, digest stri return err } - if tag.Image.Name != digest { + if tag.Image.Name != o.InputImage { return fmt.Errorf("signature identity %q does not match image %q", reference, tag.Image.Name) }