Re: Notary/TuF & GPG (& Harbor)
Scott McCarty
Per the comments on GnuPG - the ubiquitous use of GPG is what drove Red Hat to work on what we call "simple signing" [1][2]. We would love to partner on more of this work.
toggle quoted messageShow quoted text
[1]: http://www.projectatomic.io/blog/2016/07/working-with-containers-image-made-easy/ [2]: https://access.redhat.com/articles/2750891 Best Regards Scott M
On 06/20/2017 05:23 PM, Alexis Richardson via cncf-toc wrote:
Thanks Richard. +1 on .debs. My 2c is that signing functionality used to be quite inhumane, and any project seeking to do better could certainly focus on being "pleasant". Although the Notary didn't highlight this specifically, it sounded like they haven't ignored it either. --
Scott McCarty, RHCA Technical Product Marketing: Containers Email: smccarty@... Phone: 312-660-3535 Cell: 330-807-1043 Web: http://crunchtools.com When should you split your application into multiple containers? http://red.ht/22xKw9i
|
|