- Nordic Software Security Summit - https://nsss.se -

Securing the Software supply chain: Artefact and Commit Signing

Joost van Dijk [1], Yubico

Joost van Dijk, Yubico
Joost van Dijk, Yubico

One part of securing your software supply chain is to make sure that artefacts and developer commits are signed – but how does it all work? During this workshop, Joost van Dijk will take the participants through the world of digital signatures.

The workshop will explain the technologies and concepts involved, sush as PGP, PIV, FIDO, WebAuthn, SSH, PKCS#11, PKI, Certificates, and MFA.

It will focus on using cryptographic hardware, such as security keys, smartcards, and HSMs, with practical examples using FIDO Security Keys, YubiKeys, and YubiHSMs.

Some of the use cases that will be covered include:

It will also touch on recent initiatives such as Sigstore and OpenPubKey.

Prerequisites: participants are expected to have working knowledge on cryptography, git, ssh, and using command-line tools.

nsse24-yubico-joostvandijk [2]

Open Source Security Foundation
[7]
[8]