Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open-source signing infrastructure #118

Closed
dblock opened this issue Jul 29, 2021 · 5 comments
Closed

Open-source signing infrastructure #118

dblock opened this issue Jul 29, 2021 · 5 comments
Assignees
Labels
enhancement New Enhancement

Comments

@dblock
Copy link
Member

dblock commented Jul 29, 2021

Is your feature request related to a problem? Please describe.
We've developed a service that does signing. Open-source it.

@dblock dblock added the enhancement New Enhancement label Jul 29, 2021
@anirudha anirudha self-assigned this Jul 29, 2021
@peterzhuamazon
Copy link
Member

We will not open source the signer client for now.

@dblock
Copy link
Member Author

dblock commented Nov 1, 2021

Is this final or is it a matter of time? If it's the former, I'd like to understand here what the plan for publicly reproducible signing infrastructure is, and if it's the latter, I'd like to reopen the issue.

@peterzhuamazon
Copy link
Member

Is this final or is it a matter of time? If it's the former, I'd like to understand here what the plan for publicly reproducible signing infrastructure is, and if it's the latter, I'd like to reopen the issue.

@peternied could you explain more in details to @dblock I think our decision is this is reproducible with gpg and it is not necessarily that we would want to open source the internal code to run the signing process.

@dblock
Copy link
Member Author

dblock commented Nov 1, 2021

Is this final or is it a matter of time? If it's the former, I'd like to understand here what the plan for publicly reproducible signing infrastructure is, and if it's the latter, I'd like to reopen the issue.

@peternied could you explain more in details to @dblock I think our decision is this is reproducible with gpg and it is not necessarily that we would want to open source the internal code to run the signing process.

That's fine, I am looking for an issue for replacing the existing signing infrastructure with gpg, then.

@peternied
Copy link
Member

For our maven artifacts this is relatively straight forward using GPG. We can make this process more transparent - do you have an example of what you would to align towards?

Our other platforms like Mac/Windows signing processes are Amazon internal and would require considerable work to make accessible.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New Enhancement
Projects
None yet
Development

No branches or pull requests

4 participants