<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Replacement for Docker Content Trust (DCT)]]></title><description><![CDATA[<p dir="auto">What do others use for ensuring the authenticity of images after downloading them with <code>docker pull</code>?</p>
<p dir="auto">We’ve setup our CI build process to use docker for consistent, cross-platform builds. To ensure that our builds don’t use a malicious docker image (because the surface area of attack with TLS is <em>enormous</em> if you’re using X.509), we’ve been using DCT (Docker Content Trust).</p>
<p dir="auto">Unfortunately, I just discovered that the official docker documentation says that DCT is being deprecated. Apparently this was announced last year, and in June this blog post was published with advice:</p>
<ul>
<li><a href="https://www.docker.com/blog/docker-content-trust-retirement-and-migration-guidance/" rel="nofollow ugc">https://www.docker.com/blog/docker-content-trust-retirement-and-migration-guidance/</a></li>
</ul>
<h1>Cosign is not secure</h1>
<p dir="auto">We spent some time looking into cosign, but we discovered that the private keys aren't actually in the hands of the developer.</p>
<p dir="auto">Rather, they use <a href="https://docs.sigstore.dev/" rel="nofollow ugc">this complicated setup</a> using <a href="https://security.stackexchange.com/questions/234052/where-can-i-find-a-list-of-all-government-agencies-with-cas-in-pki-root-stores" rel="nofollow ugc">very insecure X.509</a> to issue temporary certificates.</p>
<p dir="auto">The result is that the OIDC identity provider (e.g., GitHub) <a href="https://medium.com/@raihanshamnad93/cosigns-keyless-verification-didn-t-match-our-threat-model-021da5cb121c" rel="nofollow ugc">extends the vector of attack <em>significantly</em></a> -- to probably <a href="https://devops.stackexchange.com/a/21734/22501" rel="nofollow ugc">tens of thousands of people</a> -- that can publish a malicious image that will be accepted by cosign as "trusted"</p>
<h1>Notation (Notary v2)</h1>
<p dir="auto">I also looked at Notation (aka “Notary v2”), but there’s no way to bootstrap the software safely, since (perplexingly) their tool for verifying the authenticity of images using cryptographic signatures itself <a href="https://github.com/notaryproject/notation/issues/1355" rel="nofollow ugc">can’t be verified using a cryptographic signature</a>.</p>
<h1>Alternatives</h1>
<p dir="auto">Are there any other alternatives that I can use to replace DCT to ensure the authenticity (using cryptography) of the container images that I download -- where the keys are actually held by the developer (thus significantly reducing the "insider threat" risk)?</p>
<p dir="auto">What do you (or does your org do) to ensure that you’re not using maliciously-modified containers after pulling a new docker image?</p>
]]></description><link>https://forum.ieu.app/topic/074ac39a-8a4d-4f72-816e-d24681298754/replacement-for-docker-content-trust-dct</link><generator>RSS for Node</generator><lastBuildDate>Sat, 05 Sep 2026 18:07:31 GMT</lastBuildDate><atom:link href="https://forum.ieu.app/topic/074ac39a-8a4d-4f72-816e-d24681298754.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 25 Aug 2026 17:31:58 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Replacement for Docker Content Trust (DCT) on Tue, 25 Aug 2026 18:26:52 GMT]]></title><description><![CDATA[<p dir="auto">Not sure of you can convert a text post to a cross post.</p>
<p dir="auto">At the least you could add a link to one post to hopefully gather the answers.</p>
]]></description><link>https://forum.ieu.app/post/https://lemmy.world/comment/25482671</link><guid isPermaLink="true">https://forum.ieu.app/post/https://lemmy.world/comment/25482671</guid><dc:creator><![CDATA[slazer2au@lemmy.world]]></dc:creator><pubDate>Tue, 25 Aug 2026 18:26:52 GMT</pubDate></item><item><title><![CDATA[Reply to Replacement for Docker Content Trust (DCT) on Tue, 25 Aug 2026 18:26:37 GMT]]></title><description><![CDATA[<p dir="auto">With cryptographically signed images, you don't need to trust Docker Hub nor the source code nor the base image. You just verify the signature that could only have been made from the developer. You trust the private key and the developer only, which significantly reduces the vector of attack (publishing infrastructure, X.509, docker hub admins, etc) by magnitudes.</p>
]]></description><link>https://forum.ieu.app/post/https://slrpnk.net/comment/24031324</link><guid isPermaLink="true">https://forum.ieu.app/post/https://slrpnk.net/comment/24031324</guid><dc:creator><![CDATA[maltfield@slrpnk.net]]></dc:creator><pubDate>Tue, 25 Aug 2026 18:26:37 GMT</pubDate></item><item><title><![CDATA[Reply to Replacement for Docker Content Trust (DCT) on Tue, 25 Aug 2026 18:24:02 GMT]]></title><description><![CDATA[<p dir="auto">Thanks. I assumed the client would figure it out automatically, but I guess that only works for links?</p>
<p dir="auto">Is there a way to edit a post to indicate it's a cross-post?</p>
]]></description><link>https://forum.ieu.app/post/https://slrpnk.net/comment/24031278</link><guid isPermaLink="true">https://forum.ieu.app/post/https://slrpnk.net/comment/24031278</guid><dc:creator><![CDATA[maltfield@slrpnk.net]]></dc:creator><pubDate>Tue, 25 Aug 2026 18:24:02 GMT</pubDate></item><item><title><![CDATA[Reply to Replacement for Docker Content Trust (DCT) on Tue, 25 Aug 2026 18:15:58 GMT]]></title><description><![CDATA[<p dir="auto">You should use the cross post feature in Lemmy, the two square overlapping in the default UI, you have made 14 posts so answers are going to be all over the place.</p>
<p dir="auto">With a cross posted post it consolidates a lot of replies to one post.</p>
]]></description><link>https://forum.ieu.app/post/https://lemmy.world/comment/25482489</link><guid isPermaLink="true">https://forum.ieu.app/post/https://lemmy.world/comment/25482489</guid><dc:creator><![CDATA[slazer2au@lemmy.world]]></dc:creator><pubDate>Tue, 25 Aug 2026 18:15:58 GMT</pubDate></item><item><title><![CDATA[Reply to Replacement for Docker Content Trust (DCT) on Tue, 25 Aug 2026 18:12:25 GMT]]></title><description><![CDATA[<p dir="auto">If you are pulling a docker hub image you already trust the source code, the base image, and the built image.</p>
<p dir="auto">Building from source means you only need to trust 2 of those things now.</p>
<p dir="auto">You can mirror the repo to your own corporate forge and run tests to make sure things are OK but at some point you do have to trust someone.</p>
]]></description><link>https://forum.ieu.app/post/https://lemmy.world/comment/25482434</link><guid isPermaLink="true">https://forum.ieu.app/post/https://lemmy.world/comment/25482434</guid><dc:creator><![CDATA[slazer2au@lemmy.world]]></dc:creator><pubDate>Tue, 25 Aug 2026 18:12:25 GMT</pubDate></item><item><title><![CDATA[Reply to Replacement for Docker Content Trust (DCT) on Tue, 25 Aug 2026 18:04:06 GMT]]></title><description><![CDATA[<p dir="auto">but how do you verify the sources of what you're fetching?</p>
<p dir="auto">Is it coming from an unsigned git repo? That seems equally vulnerable..</p>
]]></description><link>https://forum.ieu.app/post/https://slrpnk.net/comment/24030939</link><guid isPermaLink="true">https://forum.ieu.app/post/https://slrpnk.net/comment/24030939</guid><dc:creator><![CDATA[maltfield@slrpnk.net]]></dc:creator><pubDate>Tue, 25 Aug 2026 18:04:06 GMT</pubDate></item><item><title><![CDATA[Reply to Replacement for Docker Content Trust (DCT) on Tue, 25 Aug 2026 17:52:17 GMT]]></title><description><![CDATA[<p dir="auto">I tend to build my own containers for anything that matters, but that might not be a viable option.</p>
]]></description><link>https://forum.ieu.app/post/https://lemmy.radio/comment/15593923</link><guid isPermaLink="true">https://forum.ieu.app/post/https://lemmy.radio/comment/15593923</guid><dc:creator><![CDATA[vk6flab@lemmy.radio]]></dc:creator><pubDate>Tue, 25 Aug 2026 17:52:17 GMT</pubDate></item></channel></rss>