Images in cr.fermihdi.io are signed with
cosign. Verify with:
cosign verify --key https://keys.fermihdi.io/cosign.pub \ --insecure-ignore-tlog=true \ cr.fermihdi.io/<project>/<repo>:<tag>
--insecure-ignore-tlog is required because signatures are kept off
the public Sigstore transparency log, so private image names are not disclosed.
It does not weaken the check against the key.
| File | Subject | Expires |
|---|---|---|
| root_ca.pem | FermiHDI Ltd. root — CN=root.fermihdi.com | 2046-02-05 |
| lic_ica.pem | Licensing intermediate, issued by the root | 2036-04-03 |
Verify these out-of-band before trusting anything fetched from this page.
| Key | SHA-256 |
|---|---|
| cosign.pub | e8dc6115257e99f0e1e098145a0501859621fa2842f0217fb0aabae286201f79 |
| root_ca.pem | E9:4B:12:2E:84:B2:CE:5B:17:87:EB:1C:2E:4B:F5:89:8A:F9:F9:EB:2D:C0:EA:89:4E:07:2D:9F:DE:B4:6E:4A |
| lic_ica.pem | 09:6E:97:62:3C:12:6D:D7:34:01:90:74:7F:6A:F4:33:7B:23:13:A2:80:A1:13:99:EF:55:75:13:FD:A5:19:B4 |