Overview
Explore the concept of "keyless" code signing without relying on Sigstore's Fulcio in this informative conference talk. Discover how to achieve a convenient signing flow with your own trust root by leveraging existing PKI solutions such as Vault and stepca. Gain insights into the true meaning of keyless signing and learn practical configurations to implement this hassle-free approach, eliminating the need for private key management. Delve into alternative methods that offer the same benefits as Fulcio's popular keyless signing technique, empowering you to enhance your code signing processes.
Syllabus
"Keyless" Code Signing Without Fulcio - Nathan Smith, Chainguard
Taught by
CNCF [Cloud Native Computing Foundation]