Enterprise wide Git commit signing

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Hello Git Users,

My name is Ethan Rahn and I lead Product Security at Arista Networks.
I recently completed work on a project which I wanted to highlight for
everyone on this list. This is a means for allowing an enterprise to
centrally manage code signing keys for all engineers, enforce the
signing of all git commits, and audit that the source code repository
was not altered after signing. You can read the full blog post here:
https://eos.arista.com/commit-signing-with-git-at-enterprise-scale/ .
Part of what makes this so exciting to me is that I haven't seen
commit signing done at this level before, especially not with having
the repo be auditable after the fact. By having the repo be auditable
the level of vulnerable infrastructure can be reduced to the code
signing keystore; in other words the code repository can be validated
at any time to ensure it was not tampered with.

I think that the work done here is very interesting because I have not
seen it done elsewhere. Supply chain attacks through source code
repositories are a real problem. The solution in most cases seems to
be setting up a security perimeter around the repository and checking
for unauthorized accesses. If an unauthorized access does occur, or
credentials are stolen, it is hard to know the complete set of
unauthorized changes made, especially if they are mixed with
legitimate work of a number of users over a period of time.

Happy to answer any questions around this or take comments. The work
around key management has been open sourced ( references in the blog
post ) so that the open source community can benefit from this.

Cheers,

Ethan



[Index of Archives]     [Linux Kernel Development]     [Gcc Help]     [IETF Annouce]     [DCCP]     [Netdev]     [Networking]     [Security]     [V4L]     [Bugtraq]     [Yosemite]     [MIPS Linux]     [ARM Linux]     [Linux Security]     [Linux RAID]     [Linux SCSI]     [Fedora Users]

  Powered by Linux