FermiHDI public keys

Container image signing

Images in cr.fermihdi.io are signed with cosign. Verify with:

cosign verify --key https://keys.fermihdi.io/cosign.pub \
  --insecure-ignore-tlog=true \
  cr.fermihdi.io/<project>/<repo>:<tag>

--insecure-ignore-tlog is required because signatures are kept off the public Sigstore transparency log, so private image names are not disclosed. It does not weaken the check against the key.

Certificate authorities

FileSubjectExpires
root_ca.pemFermiHDI Ltd. root — CN=root.fermihdi.com2046-02-05
lic_ica.pemLicensing intermediate, issued by the root2036-04-03

Fingerprints

Verify these out-of-band before trusting anything fetched from this page.

KeySHA-256
cosign.pube8dc6115257e99f0e1e098145a0501859621fa2842f0217fb0aabae286201f79
root_ca.pemE9:4B:12:2E:84:B2:CE:5B:17:87:EB:1C:2E:4B:F5:89:8A:F9:F9:EB:2D:C0:EA:89:4E:07:2D:9F:DE:B4:6E:4A
lic_ica.pem09:6E:97:62:3C:12:6D:D7:34:01:90:74:7F:6A:F4:33:7B:23:13:A2:80:A1:13:99:EF:55:75:13:FD:A5:19:B4