Sigstore: Secure and Scalable Infrastructure for Signing and Verifying Software

QCon New York 2023

Session Security

Sigstore: Secure and Scalable Infrastructure for Signing and Verifying Software

Tuesday Jun 13 / 11:50AM EDT, Dumbo / Navy Yard

Abstract

Sigstore is an open-source project that aims to provide a transparent and secure way to sign and verify software artifacts. It is an initiative that is part of the Open Source Security Foundation (OpenSSF), and it aims to establish standards for software signing that are both easy to use and widely adopted.

Sigstore can sign and verify any software artifact, including container images, source code, NPM packages, and more! It provides a simple and easy-to-use API for developers, as well as command-line tools and integrations with popular software development platforms.

In this talk, we'll dive into the architecture and internals of Sigstore and keyless signing, along with the security considerations that drove the design. We'll examine how you can reuse your existing identity infrastructure to produce signed artifacts without worrying about protecting long-lived keys. We'll also examine how you can use these signatures to enforce runtime policies on signing identities.

Topics

Security Cloud Native Software Supply Chain Security
76% senior dev or higher
1:11 speaker ratio
60+ practitioners

QCon New York 2023 is a three day conference for senior software engineers, architects and team leads. An international program committee of working engineers selects every session. Patterns and practices, not products and pitches.

Share

From the same track

Tuesday 13 June

10:35 Dumbo / Navy Yard Session WebAssembly Wasm: What is Universal Compute Good For? Sean Isom Senior Engineer @Adobe 11:50 Dumbo / Navy Yard Session Security Sigstore: Secure and Scalable Infrastructure for Signing and Verifying Software Billy Lynch, Zack Newman 13:40 Dumbo / Navy Yard Session WebAssembly Build Features Faster With WebAssembly Components Bailey Hayes Director @Cosmonic 14:55 Dumbo / Navy Yard Session jvm Virtual Threads for Lightweight Concurrency and Other JVM Enhancements Ron Pressler Technical Lead OpenJDK's Project Loom @Oracle 16:10 Dumbo / Navy Yard Session Software Supply Chain Security Achieving SLSA Certification with a “Bring-Your-Own-Builder” Framework Asra Ali Software Engineer @Google 17:25 Dumbo / Navy Yard Session Software Supply Chain Security Securing the Software Supply Chain: How in-toto and TUF Work Together to Combat Supply Chain Attacks Marina Moore PhD Candidate @NYU & Tech Lead for CNCF's TAG Security