Enable google, envvar cosign OIDC providers. #158
Merged
Chainguard Enforce / Enforce - Commit Signing
succeeded
Apr 25, 2024 in 1s
Successfully verified commit signature.
CLAIM | DESCRIPTION | |
---|---|---|
✅ | Found Git signature | |
✅ | Validated Git signature | |
✅ | Validated Rekor entry | |
✅ | Allowed by policy |
Details
Certificate
Certificate:
Data:
Version: 3 (0x2)
Serial Number: 718138796183338767920121963029344668911431817619 (0x7dca75150cb169e43844c20ac749f1e782379993)
Signature Algorithm: ECDSA-SHA384
Issuer: O=sigstore.dev,CN=sigstore-intermediate
Validity
Not Before: Apr 25 16:31:36 2024 UTC
Not After : Apr 25 16:41:36 2024 UTC
Subject: Subject Public Key Info:
Public Key Algorithm: ECDSA
Public-Key: (256 bit)
X:
ca:55:ed:cb:82:57:bb:fe:42:a8:fe:59:ec:ac:83:
de:c0:b3:c1:15:03:11:dd:a0:b6:d2:1d:e1:55:75:
b3:72
Y:
d7:b2:1f:55:cf:58:f0:fb:de:a2:64:87:b8:49:33:
49:b9:af:26:22:dc:da:84:2d:ae:16:ae:8e:7c:aa:
4f:74
Curve: P-256
X509v3 extensions:
X509v3 Key Usage: critical
Digital Signature
X509v3 Extended Key Usage:
Code Signing
X509v3 Subject Key Identifier:
49:4C:9A:C4:F8:30:F3:4E:5A:90:1F:0D:7A:4B:F8:88:CE:88:7D:D3
X509v3 Authority Key Identifier:
keyid:DF:D3:E9:CF:56:24:11:96:F9:A8:D8:E9:28:55:A2:C6:2E:18:64:3F
X509v3 Subject Alternative Name: critical
email:billy@chainguard.dev
oidcIssuer:
https://accounts.google.com
Unknown extension 1.3.6.1.4.1.57264.1.8
Signed Certificate Timestamp:
BHoAeAB2AN09MGrGxxEyYxkeHJlnNwKiSl643jyt/4eKcoAvKe6OAAABjxYZH2kAAAQDAEcwRQIhAMatTDk2alP0N2qpVKOIhgSyFbOztqN1cEBTVxjMRTrrAiA4vv4eM341CSQ86dDDKiy66NwltrH8RWj3vNEju8coEg==
Signature Algorithm: ECDSA-SHA384
30:65:02:30:61:0c:00:85:c7:59:74:bf:a8:30:12:23:af:17:
bb:bc:e5:93:ac:26:1b:34:5b:56:ed:2d:3b:86:44:bc:9e:b6:
61:8d:bb:1e:06:aa:52:4a:6f:fb:05:2f:a6:12:ec:4f:02:31:
00:c4:5b:d0:80:27:91:6f:77:05:e9:9e:92:b9:1a:fe:55:d0:
b3:f3:fc:6f:37:bd:dc:b4:7a:2d:7c:3e:dd:57:1d:5d:03:90:
e5:90:68:a7:c8:73:35:b9:8d:67:8b:da:40
Rekor Entry
{
"body": "eyJhcGlWZXJzaW9uIjoiMC4wLjEiLCJraW5kIjoiaGFzaGVkcmVrb3JkIiwic3BlYyI6eyJkYXRhIjp7Imhhc2giOnsiYWxnb3JpdGhtIjoic2hhMjU2IiwidmFsdWUiOiI2YjgzOWEwZGM4M2Q2YjJjZDVjMjZiZWQ1NmRmYTJhNTZiNGQ4YzJkNmRmNWQzNzM1MjJkYTAxNmFkOGU4MGQ3In19LCJzaWduYXR1cmUiOnsiY29udGVudCI6Ik1FWUNJUURnSzNEUE91dEY0bVRBODhTbTlwRFhGK1ZLdUFXaDFVWHY1enZXZWk1L1N3SWhBTUJNcEREcGs0bXdKZXQrUkRiUDNNaUY0Z2dlbGRJUFlkMXVXbUdtbFA1YSIsInB1YmxpY0tleSI6eyJjb250ZW50IjoiTFMwdExTMUNSVWRKVGlCRFJWSlVTVVpKUTBGVVJTMHRMUzB0Q2sxSlNVTjZWRU5EUVd4UFowRjNTVUpCWjBsVlptTndNVVpSZVhoaFpWRTBVazFKUzNnd2JuZzFORWt6YlZwTmQwTm5XVWxMYjFwSmVtb3dSVUYzVFhjS1RucEZWazFDVFVkQk1WVkZRMmhOVFdNeWJHNWpNMUoyWTIxVmRWcEhWakpOVWpSM1NFRlpSRlpSVVVSRmVGWjZZVmRrZW1SSE9YbGFVekZ3WW01U2JBcGpiVEZzV2tkc2FHUkhWWGRJYUdOT1RXcFJkMDVFU1RGTlZGbDZUVlJOTWxkb1kwNU5hbEYzVGtSSk1VMVVXVEJOVkUweVYycEJRVTFHYTNkRmQxbElDa3R2V2tsNmFqQkRRVkZaU1V0dldrbDZhakJFUVZGalJGRm5RVVY1YkZoMGVUUktXSFV2TlVOeFVEVmFOMHQ1UkROelEzcDNVbFZFUldReVozUjBTV1FLTkZaV01YTXpURmh6YURsV2VqRnFkeXM1Tm1sYVNXVTBVMVJPU25WaE9HMUpkSHBoYUVNeWRVWnhOazltUzNCUVpFdFBRMEZZU1hkblowWjFUVUUwUndwQk1WVmtSSGRGUWk5M1VVVkJkMGxJWjBSQlZFSm5UbFpJVTFWRlJFUkJTMEpuWjNKQ1owVkdRbEZqUkVGNlFXUkNaMDVXU0ZFMFJVWm5VVlZUVlhsaENuaFFaM2M0TURWaGEwSTRUbVZyZGpScFRUWkpabVJOZDBoM1dVUldVakJxUWtKbmQwWnZRVlV6T1ZCd2VqRlphMFZhWWpWeFRtcHdTMFpYYVhocE5Ga0tXa1E0ZDBsbldVUldVakJTUVZGSUwwSkNaM2RHYjBWVldXMXNjMkpJYkVGWk1taG9ZVmMxYm1SWFJubGFRelZyV2xoWmQwdFJXVXRMZDFsQ1FrRkhSQXAyZWtGQ1FWRlJZbUZJVWpCalNFMDJUSGs1YUZreVRuWmtWelV3WTNrMWJtSXlPVzVpUjFWMVdUSTVkRTFEYzBkRGFYTkhRVkZSUW1jM09IZEJVV2RGQ2toUmQySmhTRkl3WTBoTk5reDVPV2haTWs1MlpGYzFNR041Tlc1aU1qbHVZa2RWZFZreU9YUk5TVWRMUW1kdmNrSm5SVVZCWkZvMVFXZFJRMEpJZDBVS1pXZENORUZJV1VFelZEQjNZWE5pU0VWVVNtcEhValJqYlZkak0wRnhTa3RZY21wbFVFc3pMMmcwY0hsblF6aHdOMjgwUVVGQlIxQkdhR3RtWVZGQlFRcENRVTFCVW5wQ1JrRnBSVUY0Y1RGTlQxUmFjVlV2VVROaGNXeFZielJwUjBKTVNWWnpOMDh5YnpOV2QxRkdUbGhIVFhoR1QzVnpRMGxFYVNzdmFEUjZDbVpxVlVwS1JIcHdNRTFOY1V4TWNtOHpRMWN5YzJaNFJtRlFaVGd3VTA4M2VIbG5VMDFCYjBkRFEzRkhVMDAwT1VKQlRVUkJNbWRCVFVkVlEwMUhSVTBLUVVsWVNGZFlVeTl4UkVGVFNUWTRXSFUzZW14ck5uZHRSM3BTWWxaMU1IUlBORnBGZGtvMk1sbFpNamRJWjJGeFZXdHdkaXQzVlhad2FFeHpWSGRKZUFwQlRWSmlNRWxCYm10WE9UTkNaVzFsYTNKcllTOXNXRkZ6TDFBNFlucGxPVE5NVWpaTVdIY3JNMVpqWkZoUlQxRTFXa0p2Y0Rob2VrNWliVTVhTkhaaENsRkJQVDBLTFMwdExTMUZUa1FnUTBWU1ZFbEdTVU5CVkVVdExTMHRMUW89In19fX0=",
"integratedTime": 1714062696,
"logID": "c0d23d6ad406973f9559f3ba2d1ca01f84147d8ffc5b8445c224f98b9591801d",
"logIndex": 88672193,
"verification": {
"inclusionProof": {
"checkpoint": "rekor.sigstore.dev - 2605736670972794746\n84510035\n/pQt45OS728XFON+RXCcWzvTJe0ka6Sdhc/lEDBOQWI=\n\n— rekor.sigstore.dev wNI9ajBFAiEAmsDTzzs5gU++yqO2Dc7l9s2pN607sKNkpz9TpRmWUbwCICuBtWPIJPvZwoXXA+Ge2IuytwY6PzsZMgTIBxCTa2KL\n",
"hashes": [
"c5780355c20c141e17e3a7b42c41a77b4569b2a6ed7ff9b03561c06ef9bdc869",
"dd1b8736a852b2857486b3f1ddd6baea8e489f4cc4a75f5c3e69288fa8f75b46",
"4dde31f2c653564441379576a33eafcacf38c0aa9bf5cfefe807100d7cf1d603",
"f9b5c651646d39e236a866673e3a7ccb01e38ca462ad6aae6f54ba99bca83415",
"02c308d31bef1bf43f535f7a660f28634319bf1e3cc8c9ab2acdbcacd4acab7c",
"c287cc990173a6d5ddc2e712c46828b9d5202e7aa43c61faa2382869ff5f6dfb",
"bc443f3387f321121032569454c1b2390af00666d6ef6a29d3c52c68359db8ad",
"9ff9df327366078f05b5b69bc65898cf5b6c2dd6528be5c90944f49472696a8a",
"6e0ecf6727cb05797fc1a829c90c5ad3d3ae2935c58991feafd2458aa94b7044",
"495e7733fcea92f8e8fc00d06eec0a2de91a55305cefdcd46fdee65baa017ed8",
"4d5d3209c56218e010e72223f32cc365e1d2058f9dff261b23ff294b3e8eb44b",
"f5d755a7112d07d574ba30fef187c2deec4bb2e12bca57f704e074cebd5ab016",
"7ebcc8565a303be79557e4aa6b8f33246a3cab11db57263ea27999c53afa8d69",
"40421adea5710fda1d5afbfb953704bc6e05175cc10087f81858170ed582bf5e",
"b23a2193fdc34087d74e07ffe57a70b5d17bc8d6eb7fc63290e307af50b20584",
"f7c7a7ccc682fb1e6808cbc8650039cfcbeed9aa4330216f13ff77e4d7ee3f0f"
],
"logIndex": 84508762,
"rootHash": "fe942de39392ef6f1714e37e45709c5b3bd325ed246ba49d85cfe510304e4162",
"treeSize": 84510035
},
"signedEntryTimestamp": "MEUCIQDcZLtiUrexx00Xdj9jJIecAxhfjM9Aa2eBJKZXKBC8zgIgNQEUjoXUe6lyRyVhPt5oYDCd6cWizksWArMXKT5FbMo="
}
}
Loading