Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Using gitsign without rekor #544

Open
avidal opened this issue Jul 23, 2024 · 0 comments
Open

Using gitsign without rekor #544

avidal opened this issue Jul 23, 2024 · 0 comments
Labels
bug Something isn't working

Comments

@avidal
Copy link

avidal commented Jul 23, 2024

Not a bug, but perhaps a feature request?

I'm interested in perhaps running my own sigstore deployment at work for commit signing. Eventually, we'd like to use it for artifact signing and other signing and attestation use-cases.

However, in the interest of a "quick start", I'd like to use gitsign with just fulcio for issuance. It'd get us off the ground quickly while we learn how to deploy and operationalize rekor.

Does gitsign have support for running entirely without rekor? Relatedly, does gitsign still require an active fulcio instance for offline verification (so it can assert that fulcio actually issued the certificate and is recorded in the ctlog)?

@avidal avidal added the bug Something isn't working label Jul 23, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

1 participant