Skip to content

Common Issues

Common Issues and Solutions

Container image signing with Cosign, Fulcio, and Rekor can face challenges due to misconfigurations, network constraints, or trust chain issues. Below are common problems and actionable troubleshooting steps.


1. Authentication and Key Management Issues

Problem: Signing fails due to missing or invalid signing keys, or incorrect Fulcio/Rekor credentials.
Solution:
- Verify the signing key is correctly configured and accessible:

cosign verify --key ./signing_key.pem <image-name>
- Ensure environment variables for Fulcio (e.g., FULCIO_URL, FULCIO_CA_CERT) and Rekor (e.g., REKOR_URL, REKOR_CA_CERT) are set.
- Check key permissions: The private key must be readable by the process running Cosign.

Diagram:

[User] -> [Cosign] -> [Fulcio] <-> [Rekor] <-> [Image Registry]


2. Certificate Chain and Trust Issues

Problem: Fulcio fails to issue a certificate due to invalid or incomplete certificate chains.
Solution:
- Validate the certificate chain using openssl:

openssl x509 -in certificate.pem -text -noout
- Ensure the certificate is signed by a trusted CA (e.g., a CA registered with Fulcio).
- If using self-signed certificates, explicitly trust them in Fulcio's configuration.


3. Rekor Entry Not Found or Invalid

Problem: Signature verification fails because the Rekor entry is missing or corrupted.
Solution:
- Confirm the signature was successfully recorded in Rekor:

cosign verify --signature-registry <registry-url> <image-name>
- Query Rekor directly to check the entry:
curl -X GET https://rekor.example.com/api/v1/entries/<hash>
- Re-record the entry if it’s missing (e.g., due to a failed upload).


4. Incorrect Image Reference or Registry Configuration

Problem: Signing/verification fails due to mismatched image names, tags, or registry endpoints.
Solution:
- Validate the image URI format:

docker pull <image-name>:<tag>
- Ensure the registry supports signed image metadata (e.g., AWS ECR, Harbor).
- Check registry-specific signing policies (e.g., AWS ECR requires --platform flags).


5. Network Connectivity Problems

Problem: Cosign, Fulcio, or Rekor cannot communicate due to firewall rules or DNS issues.
Solution:
- Test connectivity to Fulcio and Rekor endpoints:

curl -v https://fulcio.example.com
curl -v https://rekor.example.com
- Whitelist required ports (e.g., 443 for HTTPS) and ensure DNS resolution is correct.


6. Time Synchronization Issues

Problem: Certificate validation fails due to clock drift between systems.
Solution:
- Synchronize system clocks using NTP:

ntpdate pool.ntp.org
- Ensure all nodes (Cosign, Fulcio, Rekor) are within 5 minutes of each other.


Key takeaways

  • Verify credentials and key permissions for Cosign, Fulcio, and Rekor.
  • Validate certificate chains and ensure trust in Fulcio’s CA hierarchy.
  • Confirm Rekor entries are present and valid for signature verification.
  • Double-check image references and registry configurations.
  • Monitor network connectivity and synchronize system clocks across nodes.