Red Hat ื•ื’ื•ื’ืœ ื”ืฆื™ื’ื• ืืช Sigstore, ืฉื™ืจื•ืช ืœืื™ืžื•ืช ืงื•ื“ ืงืจื™ืคื˜ื•ื’ืจืคื™

Red Hat ื•ื’ื•ื’ืœ, ื™ื—ื“ ืขื ืื•ื ื™ื‘ืจืกื™ื˜ืช Purdue, ื”ืงื™ืžื• ืืช ืคืจื•ื™ืงื˜ Sigstore, ืฉืžื˜ืจืชื• ืœื™ืฆื•ืจ ื›ืœื™ื ื•ืฉื™ืจื•ืชื™ื ืœืื™ืžื•ืช ืชื•ื›ื ื” ื‘ืืžืฆืขื•ืช ื—ืชื™ืžื•ืช ื“ื™ื’ื™ื˜ืœื™ื•ืช ื•ืฉืžื™ืจื” ืขืœ ื™ื•ืžืŸ ืฆื™ื‘ื•ืจื™ ืœืื™ืฉื•ืจ ืžืงื•ืจื™ื•ืช (ื™ื•ืžืŸ ืฉืงื™ืคื•ืช). ื”ืคืจื•ื™ืงื˜ ื™ืคื•ืชื— ื‘ื—ืกื•ืช ื”ืขืžื•ืชื” ืœืœื ืžื˜ืจื•ืช ืจื•ื•ื— Linux Foundation.

ื”ืคืจื•ื™ืงื˜ ื”ืžื•ืฆืข ื™ืฉืคืจ ืืช ืื‘ื˜ื—ืช ืขืจื•ืฆื™ ื”ืคืฆืช ื”ืชื•ื›ื ื” ื•ื™ื’ืŸ ืžืคื ื™ ื”ืชืงืคื•ืช ืฉืžื˜ืจืชืŸ ื”ื—ืœืคืช ืจื›ื™ื‘ื™ ืชื•ื›ื ื” ื•ืชืœื•ืช (ืฉืจืฉืจืช ืืกืคืงื”). ืื—ืช ืžื‘ืขื™ื•ืช ื”ืื‘ื˜ื—ื” ื”ืžืจื›ื–ื™ื•ืช ื‘ืชื•ื›ื ืช ืงื•ื“ ืคืชื•ื— ื”ื™ื ื”ืงื•ืฉื™ ืœืืžืช ืืช ืžืงื•ืจ ื”ืชื•ื›ื ื™ืช ื•ืœืืžืช ืืช ืชื”ืœื™ืš ื”ื‘ื ื™ื™ื”. ืœื“ื•ื’ืžื”, ืจื•ื‘ ื”ืคืจื•ื™ืงื˜ื™ื ืžืฉืชืžืฉื™ื ื‘-hash ื›ื“ื™ ืœืืžืช ืืช ืชืงื™ื ื•ืช ืžื”ื“ื•ืจื”, ืืš ืœืขืชื™ื ืงืจื•ื‘ื•ืช ื”ืžื™ื“ืข ื”ื“ืจื•ืฉ ืœืื™ืžื•ืช ืžืื•ื—ืกืŸ ื‘ืžืขืจื›ื•ืช ืœื ืžื•ื’ื ื•ืช ื•ื‘ืžืื’ืจื™ ืงื•ื“ ืžืฉื•ืชืคื™ื, ื•ื›ืชื•ืฆืื” ืžื›ืš ื”ืชื•ืงืคื™ื ื™ื›ื•ืœื™ื ืœืกื›ืŸ ืืช ื”ืงื‘ืฆื™ื ื”ื“ืจื•ืฉื™ื ืœืื™ืžื•ืช ื•ืœื”ื›ื ื™ืก ืฉื™ื ื•ื™ื™ื ื–ื“ื•ื ื™ื™ื ืžื‘ืœื™ ืœืขื•ืจืจ ื—ืฉื“.

ืจืง ื—ืœืง ืงื˜ืŸ ืžื”ืคืจื•ื™ืงื˜ื™ื ืžืฉืชืžืฉ ื‘ื—ืชื™ืžื•ืช ื“ื™ื’ื™ื˜ืœื™ื•ืช ื‘ืขืช ื”ืคืฆืช ืžื”ื“ื•ืจื•ืช ื‘ืฉืœ ื”ืงืฉื™ื™ื ื‘ื ื™ื”ื•ืœ ืžืคืชื—ื•ืช, ื”ืคืฆืช ืžืคืชื—ื•ืช ืฆื™ื‘ื•ืจื™ื™ื ื•ื‘ื™ื˜ื•ืœ ืžืคืชื—ื•ืช ืฉื ืคื’ืขื•. ืขืœ ืžื ืช ืฉื”ืื™ืžื•ืช ื™ื”ื™ื” ื”ื’ื™ื•ื ื™, ื™ืฉ ืฆื•ืจืš ื’ื ืœืืจื’ืŸ ืชื”ืœื™ืš ืืžื™ืŸ ื•ืžืื•ื‘ื˜ื— ืœื”ืคืฆืช ืžืคืชื—ื•ืช ืฆื™ื‘ื•ืจื™ื™ื ื•ืกื™ื›ื•ืžื™ ื‘ื“ื™ืงื”. ืืคื™ืœื• ืขื ื—ืชื™ืžื” ื“ื™ื’ื™ื˜ืœื™ืช, ืžืฉืชืžืฉื™ื ืจื‘ื™ื ืžืชืขืœืžื™ื ืžืื™ืžื•ืช ืžื›ื™ื•ื•ืŸ ืฉื”ื ืฆืจื™ื›ื™ื ืœื”ืงื“ื™ืฉ ื–ืžืŸ ืœืœื™ืžื•ื“ ืชื”ืœื™ืš ื”ืื™ืžื•ืช ื•ืœื”ื‘ื™ืŸ ืื™ื–ื” ืžืคืชื— ืืžื™ืŸ.

Sigstore ื ื—ืฉื‘ืช ื”ืžืงื‘ื™ืœื” ืœ-Let's Encrypt ืขื‘ื•ืจ ืงื•ื“, ื•ืžืกืคืงืช ืื™ืฉื•ืจื™ื ืœื—ืชื™ืžื” ื“ื™ื’ื™ื˜ืœื™ืช ืฉืœ ืงื•ื“ ื•ื›ืœื™ื ืœืื•ื˜ื•ืžืฆื™ื” ืฉืœ ืื™ืžื•ืช. ืขื Sigstore, ืžืคืชื—ื™ื ื™ื›ื•ืœื™ื ืœื—ืชื•ื ื“ื™ื’ื™ื˜ืœื™ืช ืขืœ ื—ืคืฆื™ื ื”ืงืฉื•ืจื™ื ืœืืคืœื™ืงืฆื™ื•ืช ื›ื’ื•ืŸ ืงื‘ืฆื™ ืฉื—ืจื•ืจ, ืชืžื•ื ื•ืช ืžื™ื›ืœ, ืžื ื™ืคืกื˜ื™ื ื•ืงื•ื‘ืฆื™ ื”ืคืขืœื”. ืชื›ื•ื ื” ืžื™ื•ื—ื“ืช ืฉืœ Sigstore ื”ื™ื ืฉื”ื—ื•ืžืจ ื”ืžืฉืžืฉ ืœื—ืชื™ืžื” ื‘ื ืœื™ื“ื™ ื‘ื™ื˜ื•ื™ ื‘ื™ื•ืžืŸ ืฆื™ื‘ื•ืจื™ ื—ืกื™ืŸ ื—ื‘ืœื” ืฉื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ื• ืœืื™ืžื•ืช ื•ื‘ื™ืงื•ืจืช.

ื‘ืžืงื•ื ืžืคืชื—ื•ืช ืงื‘ื•ืขื™ื, Sigstore ืžืฉืชืžืฉืช ื‘ืžืคืชื—ื•ืช ืืจืขื™ื™ื ืงืฆืจื™ ืžื•ืขื“, ืืฉืจ ื ื•ืฆืจื™ื ืขืœ ืกืžืš ืื™ืฉื•ืจื™ื ืฉืื•ืฉืจื• ืขืœ ื™ื“ื™ ืกืคืงื™ OpenID Connect (ื‘ื–ืžืŸ ื™ืฆื™ืจืช ืžืคืชื—ื•ืช ืœื—ืชื™ืžื” ื“ื™ื’ื™ื˜ืœื™ืช, ื”ืžืคืชื— ืžื–ื“ื”ื” ื‘ืืžืฆืขื•ืช ืกืคืง OpenID ื”ืžืงื•ืฉืจ ืœืžื™ื™ืœ). ื”ืื•ืชื ื˜ื™ื•ืช ืฉืœ ื”ืžืคืชื—ื•ืช ืžืื•ืžืชืช ื‘ืืžืฆืขื•ืช ื™ื•ืžืŸ ืžืจื•ื›ื– ืฆื™ื‘ื•ืจื™, ื”ืžืืคืฉืจ ืœื•ื•ื“ื ืฉืžื—ื‘ืจ ื”ื—ืชื™ืžื” ื”ื•ื ื‘ื“ื™ื•ืง ืžื™ ืฉื”ื•ื ืžืชื™ื™ืžืจ ืœื”ื™ื•ืช ื•ื”ื—ืชื™ืžื” ื ื•ืฆืจื” ืขืœ ื™ื“ื™ ืื•ืชื• ืžืฉืชืชืฃ ืฉื”ื™ื” ืื—ืจืื™ ืœืฉื—ืจื•ืจื™ื ื‘ืขื‘ืจ.

Sigstore ืžืกืคืงืช ื’ื ืฉื™ืจื•ืช ืžื•ื›ืŸ ืฉื›ื‘ืจ ืชื•ื›ืœื• ืœื”ืฉืชืžืฉ ื‘ื• ื•ื’ื ืกื˜ ื›ืœื™ื ื”ืžืืคืฉืจื™ื ืœื›ื ืœืคืจื•ืก ืฉื™ืจื•ืชื™ื ื“ื•ืžื™ื ืขืœ ื”ืฆื™ื•ื“ ืฉืœื›ื. ื”ืฉื™ืจื•ืช ื—ื™ื ืžื™ ืœื›ืœ ื”ืžืคืชื—ื™ื ื•ืกืคืงื™ ื”ืชื•ื›ื ื”, ื•ื”ื•ื ืคืจื•ืก ื‘ืคืœื˜ืคื•ืจืžื” ื ื™ื˜ืจืœื™ืช - ืงืจืŸ ืœื™ื ื•ืงืก. ื›ืœ ืจื›ื™ื‘ื™ ื”ืฉื™ืจื•ืช ื”ื™ื ื ื‘ืงื•ื“ ืคืชื•ื—, ื›ืชื•ื‘ื™ื ื‘-Go ื•ืžื•ืคืฆื™ื ืชื—ืช ืจื™ืฉื™ื•ืŸ Apache 2.0.

ื‘ื™ืŸ ื”ืจื›ื™ื‘ื™ื ืฉืคื•ืชื—ื• ื ื•ื›ืœ ืœืฆื™ื™ืŸ:

  • Rekor ื”ื•ื ื™ื™ืฉื•ื ื™ื•ืžืŸ ืœืื—ืกื•ืŸ ืžื˜ื ื ืชื•ื ื™ื ื—ืชื•ืžื™ื ื“ื™ื’ื™ื˜ืœื™ืช ื”ืžืฉืงืคื™ื ืžื™ื“ืข ืขืœ ืคืจื•ื™ืงื˜ื™ื. ื›ื“ื™ ืœื”ื‘ื˜ื™ื— ืฉืœืžื•ืช ื•ืœื”ื’ืŸ ืžืคื ื™ ืฉื—ื™ืชื•ืช ื ืชื•ื ื™ื ืœืื—ืจ ืžืขืฉื”, ื ืขืฉื” ืฉื™ืžื•ืฉ ื‘ืžื‘ื ื” ื“ืžื•ื™ ืขืฅ "Merkle Tree", ืฉื‘ื• ื›ืœ ืขื ืฃ ืžืืžืช ืืช ื›ืœ ื”ืขื ืคื™ื ื•ื”ืฆืžืชื™ื ื”ื‘ืกื™ืกื™ื™ื, ื”ื•ื“ื•ืช ืœื’ื™ื‘ื•ื‘ (ื“ืžื•ื™ ืขืฅ). ืœืื—ืจ ื”-hash ื”ืกื•ืคื™, ื”ืžืฉืชืžืฉ ื™ื›ื•ืœ ืœืืžืช ืืช ื ื›ื•ื ื•ืช ื›ืœ ื”ื™ืกื˜ื•ืจื™ื™ืช ื”ืคืขื•ืœื•ืช, ื›ืžื• ื’ื ืืช ื ื›ื•ื ื•ืช ืžืฆื‘ื™ ื”ืขื‘ืจ ืฉืœ ื‘ืกื™ืก ื”ื ืชื•ื ื™ื (ื”-hash ืื™ืžื•ืช ื”ืฉื•ืจืฉ ืฉืœ ื”ืžืฆื‘ ื”ื—ื“ืฉ ืฉืœ ื‘ืกื™ืก ื”ื ืชื•ื ื™ื ืžื—ื•ืฉื‘ ืชื•ืš ื”ืชื—ืฉื‘ื•ืช ื‘ืžืฆื‘ ื”ืขื‘ืจ ). ื›ื“ื™ ืœืืžืช ื•ืœื”ื•ืกื™ืฃ ืจืฉื•ืžื•ืช ื—ื“ืฉื•ืช, ืžืกื•ืคืง Restful API, ื›ืžื• ื’ื ืžืžืฉืง cli.
  • Fulcio (SigStore WebPKI) ื”ื™ื ืžืขืจื›ืช ืœื™ืฆื™ืจืช ืจืฉื•ื™ื•ืช ืื™ืฉื•ืจื™ื (Root-CAs) ื”ืžื ืคืงื•ืช ืื™ืฉื•ืจื™ื ืงืฆืจื™ ืžื•ืขื“ ื”ืžื‘ื•ืกืกื™ื ืขืœ ืื™ืžื™ื™ืœ ื”ืžืื•ืžืช ื‘ืืžืฆืขื•ืช OpenID Connect. ืžืฉืš ื”ื—ื™ื™ื ืฉืœ ื”ืื™ืฉื•ืจ ื”ื•ื 20 ื“ืงื•ืช, ื‘ืžื”ืœื›ืŸ ืขืœ ื”ืžืคืชื— ืœื”ืกืคื™ืง ืœื”ืคื™ืง ื—ืชื™ืžื” ื“ื™ื’ื™ื˜ืœื™ืช (ืื ื”ืื™ืฉื•ืจ ื™ื™ืคื•ืœ ืžืื•ื—ืจ ื™ื•ืชืจ ืœื™ื“ื™ื• ืฉืœ ืชื•ืงืฃ, ืชื•ืงืฃ ื”ืื™ืฉื•ืจ ื›ื‘ืจ ื™ืคื•ื’).
  • ะกosign (ื—ืชื™ืžืช ืžื™ื›ืœ) ื”ื™ื ืขืจื›ืช ื›ืœื™ื ืœื”ืคืงืช ื—ืชื™ืžื•ืช ืœืžื›ื•ืœื•ืช, ืื™ืžื•ืช ื—ืชื™ืžื•ืช ื•ื”ืฆื‘ืช ืžื›ื•ืœื•ืช ื—ืชื•ืžื•ืช ื‘ืžืื’ืจื™ื ื”ืชื•ืืžื™ื ืœ-OCI (Open Container Initiative).

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”