Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

TUF Delegations to Fulcio identities #401

Closed
3 tasks
mnm678 opened this issue Sep 27, 2022 · 2 comments
Closed
3 tasks

TUF Delegations to Fulcio identities #401

mnm678 opened this issue Sep 27, 2022 · 2 comments
Labels
enhancement New feature or request

Comments

@mnm678
Copy link
Contributor

mnm678 commented Sep 27, 2022

We can use the TUF root of trust to create namespaced delegations to Fulcio identities for particular artifacts. This would allow verifiers to determine which identity should be signing a given artifact.

To do so, we need a couple of things:

@mnm678 mnm678 added the enhancement New feature or request label Sep 27, 2022
@jku
Copy link
Member

jku commented Sep 4, 2024

tuf-on-ci itself supports this already (its is experimental since very few clients support the TAP) so repositories like this can be setup in minutes right now...

However

  • I suggest that we don't use this feature in root-signing
  • The specification and client support required is going to take effort that is not really a root-signing issue anyway

based on this I'm closing.

@jku jku closed this as completed Sep 4, 2024
@jku
Copy link
Member

jku commented Sep 4, 2024

(please reopen if I've misunderstood anything)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

2 participants