Linux Foundation's Latest Open-Source Project: OpenPubkey

Written by Michael Larabel in Free Software on 4 October 2023 at 09:47 AM EDT. 9 Comments
FREE SOFTWARE
The newest open-source project hosted by the Linux Foundation is OpenPubkey, which is a collaboration with Docker and BastionZero and will be available for Docker container signing with zero-trust passwordless authentication.

OpenPubkey is born out of BastionZero's secure infrastructure access product and comes down to being a protocol to securely and accurately bind cryptographic keys to users and workloads by creating a CA out of an OpenID Connect Identity Provider. The hope is OpenPubkey can help secure the software supply chain for Docker and other software projects.

OpenPubkey


OpenPubkey is intended to augment OpenID Connect. The OpenPubkey GitHub further explains:
"OpenPubkey adds user generated cryptographic signatures to OpenID Connect (OIDC) to enable users to sign messages or artifacts under their OpenID identity. Verifiers can check that these signatures are valid and associated with the signing OpenID identity. OpenPubkey does not add any new trusted parties beyond what is required for OpenID Connect and is fully compatible with existing OpenID Providers (Google, Azure/Microsoft, Okta, OneLogin, Keycloak) without any changes to the OpenID Provider."

More details on the OpenPubkey project via LinuxFoundation.org.
Related News
About The Author
Michael Larabel

Michael Larabel is the principal author of Phoronix.com and founded the site in 2004 with a focus on enriching the Linux hardware experience. Michael has written more than 20,000 articles covering the state of Linux hardware support, Linux performance, graphics drivers, and other topics. Michael is also the lead developer of the Phoronix Test Suite, Phoromatic, and OpenBenchmarking.org automated benchmarking software. He can be followed via Twitter, LinkedIn, or contacted via MichaelLarabel.com.

Popular News This Week