User-friendly, affordable, and packed with different features, DocHub is a healthy and cost-efficient alternative to SignServer Enterprise. Try it now and learn how to squeeze the maximum of our solution with easy-to-use feature shortcuts.
Anton Hodal, Solutions consultant at Key Factor, demonstrates how to use Sign Server with Cosign to sign container images. Cosign is a tool for signing and verifying container images developed by the Sigstore project. Sign Server is a digital signer for managing signing keys with auditing and archiving features. The process involves creating a signing key stored in Sign Server, generating a certificate signing request, issuing a digital signing certificate, creating a Docker image, putting it in a registry using Cosign, creating a payload for the image description, and signing it with Sign Server.