Fulcio Certificates
Fulcio is a critical component of the Sigstore ecosystem, serving as a time-bound certificate authority (CA) that issues short-lived, ephemeral certificates for secure container image signing. These certificates are used by tools like Cosign to authenticate signers and ensure the integrity of container images. By leveraging Fulcio, Sigstore enables secure, auditable, and tamper-proof signing workflows that align with modern security best practices.
How Fulcio Issues Time-Bound Certificates¶
Fulcio issues short-lived certificates (typically valid for a few hours to a few days) that are tied to specific signing operations. These certificates are signed by a long-lived root certificate (managed separately) and are designed to minimize the risk of long-term exposure if a private key is compromised. The process involves:
- Certificate Request: A user or service requests a certificate via the Fulcio API, providing identity details (e.g., a username or service account).
- Validation: Fulcio validates the request, ensuring the requester is authorized to obtain a certificate.
- Certificate Issuance: Fulcio issues a certificate with a defined validity period, which includes:
- Not Before: The certificate becomes valid.
- Not After: The certificate expires.
- Subject: The entity (e.g., a user or service) the certificate represents.
- Issuer: Fulcio itself, signed by the root CA.
- Usage: The certificate is then used by Cosign to sign container images, proving the signer's identity to downstream systems.
Example: Requesting a Certificate with Fulcio CLI¶
To interact with Fulcio, you can use its command-line interface (CLI). Here's an example of requesting a certificate:
# Request a certificate using the Fulcio CLI
fulcio request --identity "[email protected]" --output certificate.pem
This command generates a certificate valid for 24 hours (default duration). The certificate includes the subject ([email protected]) and is signed by Fulcio's root CA.
Integration with Sigstore Components¶
Fulcio works seamlessly with other Sigstore tools: - Cosign: Uses Fulcio-issued certificates to sign container images, ensuring the signer's identity is verified. - Rekor: Logs the signatures and certificates for transparency and auditability. - Sigstore CLI: Provides a unified interface for signing, verifying, and managing certificates across the ecosystem.
Diagram: Fulcio Certificate Issuance Workflow¶
[User/Service] --> [Fulcio API] --> [Certificate Issuance]
| |
v v
[Validation] [Signed Certificate]
| |
v v
[Cosign] [Rekor Log]
Key takeaways¶
- Fulcio issues time-bound certificates to limit the risk of long-term key exposure.
- Certificates are signed by a root CA and validated by Fulcio before issuance.
- Integration with Cosign and Rekor ensures secure, auditable signing workflows.
- Short-lived certificates are a core security practice in Sigstore's design.