Does SLSA prescribe a way to sign provenance?

62 views
Skip to first unread message

Clement

unread,
Oct 6, 2022, 4:23:29 AM10/6/22
to slsa-discussion
From what I've understood, SLSA defines the requirements to meet "what" and not the "how". 

I've been using Gitlab to generate provenance for artifacts but what's the recommended way sign & allow users to verify and perform attestation?

Tony Loehr

unread,
Oct 6, 2022, 11:26:04 AM10/6/22
to Clement, slsa-discussion
Hey Clement,

I can walk through this with you. What’s your calendar availability this week?

Best,
Tony

On Thu, Oct 6, 2022 at 1:23 AM Clement <transc...@gmail.com> wrote:
From what I've understood, SLSA defines the requirements to meet "what" and not the "how". 

I've been using Gitlab to generate provenance for artifacts but what's the recommended way sign & allow users to verify and perform attestation?

--
You received this message because you are subscribed to the Google Groups "slsa-discussion" group.
To unsubscribe from this group and stop receiving emails from it, send an email to slsa-discussi...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/slsa-discussion/d90e4d19-36de-4599-83d3-22ae6b7b2579n%40googlegroups.com.
--
Best,
Tony Loehr

Developer Advocate, Cycode

Abhishek Arya

unread,
Oct 6, 2022, 11:41:22 AM10/6/22
to Clement, slsa-discussion, Tony Loehr
Clement, here is the community blog post on how to generate and sign SLSA provenance.


Michael Lieberman

unread,
Oct 6, 2022, 11:52:15 AM10/6/22
to Abhishek Arya, Clement, slsa-discussion, Tony Loehr
Feel free to also ask in the #slsa channel in OpenSSF slack - https://slack.openssf.org/. We're all pretty responsive.

With that being said, there's lots of ways to generate signed attestations and verifying those attestations. There's OpenSSF projects like Sigstore but SLSA doesn't require a specific tool or technology. I also recommend taking a look at the Getting Started page: https://slsa.dev/get-started which lists a few ways.

Reply all
Reply to author
Forward
0 new messages