Admin message

Due to an influx of spam, we have had to temporarily disable account registrations. Please write an email to accountsupport@archlinux.org, with your desired username, if you want to get access. Sorry for the inconvenience.

Open
Milestone

Sign low impact artifacts

There are several contexts in which signatures are created manually or using unsecured private key material. These include signatures for installation media and virtual machines. Signing these artifacts is considered a low impact action, because the current workflow is either manual or unsecured, happens on a low cadence and adding a drop-in signature by an individual of the Arch Linux team would be possible. Further, end-user systems can not be broken or compromised by addressing these artifacts and delegated authentication for the signatures is currently only partly advertised.

For these artifacts, the signing should take place on dedicated hosts, which guard their SSH keys using the host’s integrated or discrete TPM 2.0. Such a host is then used specifically in the CI pipeline of the projects building the installation media and virtual machines. Each of these hosts rely on Signstar client software to issue signing requests and receive signatures.

  • Work items 1
  • Merge requests 0
  • Participants 0
  • Labels 1
Loading
Loading
Loading
Loading
0% complete
0%
Start date
No start date
None
Due date
No due date
1
Work items 1 New issue
Open: 1 Closed: 0
None
Total weight
None
0
Merge requests 0
Open: 0 Closed: 0 Merged: 0
0
Releases
None
Reference: archlinux/signstar%"Sign low impact artifacts"