<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Certificate Authority on</title><link>https://deploy-preview-426--docssigstore.netlify.app/certificate_authority/</link><description>Recent content in Certificate Authority on</description><generator>Hugo -- gohugo.io</generator><lastBuildDate>Tue, 06 Oct 2020 08:49:15 +0000</lastBuildDate><atom:link href="https://deploy-preview-426--docssigstore.netlify.app/certificate_authority/index.xml" rel="self" type="application/rss+xml"/><item><title>Fulcio</title><link>https://deploy-preview-426--docssigstore.netlify.app/certificate_authority/overview/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://deploy-preview-426--docssigstore.netlify.app/certificate_authority/overview/</guid><description>Fulcio is a free code signing Certificate Authority, built to make short-lived certificates available to anyone. Based on an OpenID Connect email address, Fulcio signs X.509 certificates valid for 10 minutes.
Fulcio was designed to run as a centralized, public-good instance, auditable by a certificate transparency log. Fulcio can also be deployed as a self-hosted service.
Fulcio is being developed as part of the Sigstore project. Join us on our Slack channel (need an invite?</description></item><item><title>Certificate Issuing Overview</title><link>https://deploy-preview-426--docssigstore.netlify.app/certificate_authority/certificate-issuing-overview/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://deploy-preview-426--docssigstore.netlify.app/certificate_authority/certificate-issuing-overview/</guid><description>This page will walk through the process of issuing a code signing certificate from start to finish as an entry point to understanding how Fulcio works.
1 — Certificate request input # As a first step, the client submits a certificate request to Fulcio. This certificate request contains the following:
An OpenID Connect (OIDC) identity token. This is a signed JWT containing information about the principal (identity of the client), the issuer (who issued the identity token - Google, Microsoft, GitHub, etc.</description></item><item><title>Transparency Log Info</title><link>https://deploy-preview-426--docssigstore.netlify.app/certificate_authority/cert-transparency-log-info/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://deploy-preview-426--docssigstore.netlify.app/certificate_authority/cert-transparency-log-info/</guid><description>Review Fulcio&amp;rsquo;s transparency log information on GitHub.</description></item><item><title>OIDC Usage in Fulcio</title><link>https://deploy-preview-426--docssigstore.netlify.app/certificate_authority/oidc-in-fulcio/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://deploy-preview-426--docssigstore.netlify.app/certificate_authority/oidc-in-fulcio/</guid><description>Summary # Fulcio uses OIDC tokens to authenticate requests. Subject-related claims from the OIDC token are extracted and included in issued certificates.
Sigstore runs a federated OIDC identity provider, Dex. Users authenticate to their preferred identity provider and Dex creates an OIDC token with claims from the original OIDC token. Fulcio also supports OIDC tokens from additional configured issuers.
Supported OIDC token issuers # Email # Email-based OIDC providers use the user&amp;rsquo;s email as the subject of the certificate.</description></item><item><title>Release Log</title><link>https://deploy-preview-426--docssigstore.netlify.app/certificate_authority/release-log/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://deploy-preview-426--docssigstore.netlify.app/certificate_authority/release-log/</guid><description>Review Fulcio&amp;rsquo;s Release log on GitHub.</description></item><item><title>HSM Support</title><link>https://deploy-preview-426--docssigstore.netlify.app/certificate_authority/hsm-support/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://deploy-preview-426--docssigstore.netlify.app/certificate_authority/hsm-support/</guid><description>Review Fulcio&amp;rsquo;s HSM support on GitHub.</description></item><item><title>Certificate Specification</title><link>https://deploy-preview-426--docssigstore.netlify.app/certificate_authority/cert_specification/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://deploy-preview-426--docssigstore.netlify.app/certificate_authority/cert_specification/</guid><description>Review Fulcio&amp;rsquo;s certificate specification on GitHub.</description></item></channel></rss>