8000 Alert only for certificates issued from a set of trusted roots by Horiodino · Pull Request #594 · sigstore/rekor-monitor · GitHub
[go: up one dir, main page]
More Web Proxy on the site http://driver.im/
Skip to content

Alert only for certificates issued from a set of trusted roots #594

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Draft
wants to merge 6 commits into
base: main
Choose a base branch
from

Conversation

Horiodino
Copy link
Contributor

Summary

fixes : #378 (comment)

As mentioned in the issue, this PR resolves the verification of certificate chains up to a trusted root and denies any unregistered (custom) roots.

Release Note

Documentation

Signed-off-by: Horiodino <holiodin@gmail.com>
Signed-off-by: Horiodino <holiodin@gmail.com>
Signed-off-by: Horiodino <holiodin@gmail.com>
Signed-off-by: Horiodino <holiodin@gmail.com>
Signed-off-by: Horiodino <holiodin@gmail.com>
@Horiodino Horiodino requested a review from a team as a code owner February 22, 2025 17:05
@Horiodino
Copy link
Contributor Author

draft pr , needs some more work.

Signed-off-by: Horiodino <holiodin@gmail.com>
@Horiodino Horiodino marked this pull request as draft March 16, 2025 15:38
@Horiodino
Copy link
Contributor Author

Hey @haydentherapper @bobcallaway, could you help verify the changes? Still a draft PR, but would appreciate a review when you have a moment. Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Alert only for certificates issued from a set of trusted roots
1 participant
0