The readiness of the Sigstore code cryptographic verification system has been announced.

Google has announced the creation of the first stable releases of the components forming the Sigstore project, which is deemed suitable for building production deployments. Sigstore develops tools and services for verifying software using digital signatures and maintaining a public log that verifies the authenticity of changes (transparency log). The project is being developed under the auspices of the non-profit organization Linux Foundation by Google, Red Hat, Cisco, VMware, GitHub, and HP Enterprise, with the participation of the OpenSSF (Open Source Security Foundation) and Purdue University.

Sigstore can be viewed as a Let’s Encrypt equivalent for code, providing certificates to attest code with digital signatures and tools for automating verification. With Sigstore, developers will be able to create digital signatures for application-related artifacts such as release files, container images, manifests, and executable files. The material used for signing is reflected in a tamper-proof public log that can be used for verification and auditing.

Instead of permanent keys, Sigstore uses short-lived ephemeral keys that are generated based on credentials verified by OpenID Connect providers (at the time of generating the keys needed to create a digital signature, the developer identifies themselves through the OpenID provider tied to their email). The authenticity of the keys is verified through a public centralized log that ensures the signer is who they claim to be and that the signature was created by the same participant responsible for previous releases.

Sigstore's readiness for deployment is due to the release of two key components—Rekor 1.0 and Fulcio 1.0—whose APIs have been declared stable and will maintain backward compatibility. The service components are written in Go and are distributed under the Apache 2.0 license.

The Rekor component implements a log for storing metadata that is certified by digital signatures, reflecting information about projects. To ensure integrity and protection against data tampering, a tree structure known as a 'Merkle Tree' is employed, where each branch verifies all underlying branches and nodes through hierarchical hashing. With the final hash, users can verify the correctness of the entire operation history and the accuracy of past database states (the root verification hash of the new database state is calculated with respect to the previous state). A RESTful API and a command-line interface are provided for verification and adding new entries.

The Fulcio component (SigStore WebPKI) includes a system for creating certification authorities (root CAs) that issue short-lived certificates based on email authenticated via OpenID Connect. The certificate has a lifetime of 20 minutes, during which the developer must complete the digital signature (if the certificate later gets into the hands of an attacker, it will have already expired). Additionally, the project is developing the Cosign (Container Signing) toolkit, which is intended for creating signatures for containers, verifying signatures, and storing signed containers in OCI-compatible repositories.

The implementation of Sigstore enables enhanced security for software distribution channels and protection against attacks aimed at substituting libraries and dependencies (supply chain). One of the key security challenges in open-source software is the difficulty of verifying the source of the program and the authenticity of the build process. For instance, most projects use hashes to verify the integrity of releases, but the information needed for authenticity checks is often stored in unsecured systems and shared code repositories. As a result, if these are compromised, attackers can replace the necessary verification files, infiltrating malicious changes without raising suspicion.

The use of digital signatures for verifying releases has not yet become widespread due to challenges in key management, distribution of public keys, and revocation of compromised keys. For verification to be meaningful, a reliable and secure process for distributing public keys and checksums must also be established. Even with a digital signature, many users ignore verification because it takes time to learn the verification process and understand which key is trustworthy. The Sigstore project aims to simplify and automate these processes by providing a ready-made and vetted solution.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster