You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
With linked artifacts, including Notary v2 signatures and SBoMs persistence completed in Prototype 2, we must address tag locking and key management requirements. Prototype 3 will exist with an understanding of what we might do next but isn't expected to produce a solid spec. It will validate what it would take to sign tags and manage key, and/or signature lifecycle requirements.
Goals & Intent
Implement a tag signing solution for oci-distribution-spec based registries.
The prototype should:
Experiment with how tags may be signed, with notary v2 signatures.
Experiment with how key and/or signature revocation/invalidation scenarios may be implemented, without requiring short-lived keys that must be continually updated.
2. without requiring short-lived keys that must be continually updated.
This feels like strangely specific wording :) Did anyone suggest using short-lived keys that must be continually updated? How short qualifies as "short"?
With linked artifacts, including Notary v2 signatures and SBoMs persistence completed in Prototype 2, we must address tag locking and key management requirements. Prototype 3 will exist with an understanding of what we might do next but isn't expected to produce a solid spec. It will validate what it would take to sign tags and manage key, and/or signature lifecycle requirements.
Goals & Intent
Implement a tag signing solution for oci-distribution-spec based registries.
The prototype should:
The prototype should not:
Target Experience
TBD:
Deliverables
The text was updated successfully, but these errors were encountered: