Upgrade to Pro — share decks privately, control downloads, hide ads and more …

Understanding the Identity of a CI Platform

Understanding the Identity of a CI Platform

Presented at SigstoreCon 2024

Avatar for Richard Fan

Richard Fan

November 12, 2024

More Decks by Richard Fan

Other Decks in Technology

Transcript

  1. Who am I • Security Engineer • AWS Security Hero

    • Amateur hacker OSCP – but forgot how to try harder • Love travel, hiking • Have a cat
  2. Extension verification support Not Supported Only for GitHub New OID

    scheme • sigstore-js (Was supported, but removed) • sigstore-rs (No stable release yet) • sigstore-ruby (No stable release yet) • policy-controller (Possible with attestation) • sigstore-python (CLI) • cosign • sigstore-java (With some tricks) • sigstore-python (API) • sigstore-go (Undocumented function) NewCertificateIdentity()
  3. No one size fit all If you think some mapping

    is not right? Raise a PR!! https://github.com/sigstore/fulcio/blob/main/config/identity/config.yaml