Skip to content

Commit

Permalink
Merge pull request #600 from sigstore/cleanup-old-verification-mats
Browse files Browse the repository at this point in the history
Remove unused verification materials
  • Loading branch information
loosebazooka authored Dec 28, 2023
2 parents 8d2d442 + d93b8d9 commit 76aca3e
Show file tree
Hide file tree
Showing 31 changed files with 1 addition and 804 deletions.
68 changes: 0 additions & 68 deletions sigstore-java/src/main/java/dev/sigstore/VerificationMaterial.java

This file was deleted.

20 changes: 1 addition & 19 deletions sigstore-java/src/main/resources/dev/sigstore/tuf/README.md
Original file line number Diff line number Diff line change
@@ -1,21 +1,3 @@
# TUF Store

This resource is a temporary alternative to an actual TUF client.
This is **not a permanent solution** and should not be treated as such.
If the key changes, they will not automatically be reflected here
and various signing/verification workflows will fail.

We keep copies of the remote tuf repositories locally in
1. Production from https://tuf-repo-cdn.sigstore.dev \
for interfacing with *.sigstore.dev

2. Staging from https://tuf-repo-cdn.sigstage.dev \
for interfacing with *.sigstage.dev

For this client to function we need the following keys
1. CTFE public keys (`ctfe.pub`, `ctfe_*.pub`) \
the public key for the certificate transparency log
2. Fulcio root cert (`fulcio_v1.crt.pem` or `fulcio.crt.pem`) \
the root certificate for fulcio issued certificates
3. Rekor public key (`rekor.pub`) \
the public key for the rekor transparency log
Seed roots for sigstore public good and staging.

This file was deleted.

This file was deleted.

This file was deleted.

This file was deleted.

This file was deleted.

Loading

0 comments on commit 76aca3e

Please sign in to comment.