⚡️ Enlightning - Ensuring Software Authenticity: Introduction to Notary Project

August 17, 2023

Software vendors use digital signatures to ensure authenticity and integrity of their distributed software. Cloud native workloads require support for signature delivery mechanisms, agility to address emerging needs, and hyper scalability to match application needs. In addition to consuming authentic third party and/or open source software, users also want to ensure the integrity and authenticity of software they develop to enhance software supply chain security. Cloud native workloads can benefit from a signing technology that allows customers to leverage their traditional signing infrastructure and is flexible for future innovations. Meet the Notary Project. In this episode, we will see how Notary Project tooling can be used to sign software artifacts stored in OCI-compliant registries, distributed easily across OCI-compliant registries, and verified for any container deployment, even in air-gapped environments. We’ll talk about concepts like signing schema that enable trusting multiple entities both in-house and third-party; signature formats that enable a variety of cloud-native workloads, from container images, to WASM modules and IoT workloads; and plugins that enable integrations with 3rd party key management and cloud service providers. The tooling is enterprise-ready and allows easy adoption for anyone to start signing their software artifacts. Join us to learn more.

Previous
SpringOne at VMware Explore Singapore 2023
SpringOne at VMware Explore Singapore 2023

Register at https://www.vmware.com/explore/sg/springone.html

Next Video
Explore Spring Data Abstraction for Reactive Applications
Explore Spring Data Abstraction for Reactive Applications

This video explores how Spring Data abstracts applications from the details of data source connections, dat...