Meaning
Method of securing software artifacts using short-lived certificates linked to an identity provider replaces the need for long-term private keys. Use of sigstore keyless signing reduces the risk of key theft by issuing a certificate that is only valid for a few minutes. This process relies on the OpenID Connect protocol to verify the identity of the developer at the time of the signature.
Certificate Issuance
Automated certificate authorities grant a temporary credential after a successful login through a trusted provider. During sigstore keyless signing, the public key is bound to the developer’s email address or service account for the duration of the build. This credential expires almost immediately after the signature is applied to the artifact.
Transparency Entry
Public logs record every signature and certificate issued to provide a verifiable history of all software releases. A sigstore keyless signing event is only considered valid if it can be found in the transparency log, which prevents the use of backdated or fraudulent certificates. Anyone can audit these logs to see which identities have signed which pieces of software.
Trust Logic
Verification of the artifact involves checking the transparency log rather than managing a list of public keys. Because sigstore keyless signing removes the burden of key management, it is easier for small teams to implement secure software practices. The system assumes that the identity provider is secure and that the log is immutable.