spdx: explain SHA1 usage #1501
Open
spdx: explain SHA1 usage #1501
Chainguard Enforce / Enforce - Commit Signing
succeeded
Jan 29, 2025 in 0s
Successfully verified commit signature.
CLAIM | DESCRIPTION | |
---|---|---|
✅ | Found Git signature | |
✅ | Validated Git signature | |
✅ | Validated Rekor entry | |
✅ | Allowed by policy |
Details
Certificate
Certificate:
Data:
Version: 3 (0x2)
Serial Number: 364202083802704686011317259727186215944843719692 (0x3fcb62e22b61d84216d8f56fc4cd2780b9c8740c)
Signature Algorithm: ECDSA-SHA384
Issuer: O=sigstore.dev,CN=sigstore-intermediate
Validity
Not Before: Jan 29 02:45:28 2025 UTC
Not After : Jan 29 02:55:28 2025 UTC
Subject: Subject Public Key Info:
Public Key Algorithm: ECDSA
Public-Key: (256 bit)
X:
25:a7:88:30:9c:69:53:78:d0:86:cc:52:7b:8a:14:
6b:51:df:02:9c:59:e3:66:6e:88:3a:b4:7e:c3:46:
24:21
Y:
36:26:19:83:32:b6:d3:5c:13:c3:22:1d:ce:4c:b0:
0b:54:38:6d:91:57:1d:23:e6:a5:c7:75:fa:f4:9a:
25:f9
Curve: P-256
X509v3 extensions:
X509v3 Key Usage: critical
Digital Signature
X509v3 Extended Key Usage:
Code Signing
X509v3 Subject Key Identifier:
E1:83:B1:6E:E8:5D:3C:8E:4F:61:71:70:B6:B2:D9:3B:42:9A:59:7B
X509v3 Authority Key Identifier:
keyid:DF:D3:E9:CF:56:24:11:96:F9:A8:D8:E9:28:55:A2:C6:2E:18:64:3F
X509v3 Subject Alternative Name: critical
email:[email protected]
oidcIssuer:
https://accounts.google.com
Unknown extension 1.3.6.1.4.1.57264.1.8
Signed Certificate Timestamp:
BHsAeQB3AN09MGrGxxEyYxkeHJlnNwKiSl643jyt/4eKcoAvKe6OAAABlK/zCnAAAAQDAEgwRgIhALS3Q46OPMsqjKxF4YtHxopHHA0q21+HW9W3apuuQhmqAiEAl7TRCPv/qZ6Vt0T3i81erCG2c48uqtXmtErN2Ic+brM=
Signature Algorithm: ECDSA-SHA384
30:64:02:30:63:e1:a4:38:16:64:29:70:ce:7e:fb:2a:cc:6c:
04:09:1d:ac:e6:a3:e2:f8:e9:d3:90:a8:a6:30:cd:7e:48:7c:
12:b9:c0:99:ff:94:ef:47:eb:b0:76:f4:e6:9c:1c:91:02:30:
23:70:e0:c5:dc:77:fa:55:5e:a1:e8:66:91:75:39:1c:c9:da:
f9:45:bd:34:f5:f5:06:e4:61:22:77:e8:92:2c:24:a6:d4:83:
22:26:cf:c1:8a:80:d5:ba:4a:cb:d6:76
Rekor Entry
{
"body": "eyJhcGlWZXJzaW9uIjoiMC4wLjEiLCJraW5kIjoiaGFzaGVkcmVrb3JkIiwic3BlYyI6eyJkYXRhIjp7Imhhc2giOnsiYWxnb3JpdGhtIjoic2hhMjU2IiwidmFsdWUiOiI2MmQyNDVhN2IyNDI3MzlkN2JmMjBjODBkMTkxMDQ0ODExMjhhNjY5NTJiYjBjMmEwN2RmZWVjYTg5NmZkZjNiIn19LCJzaWduYXR1cmUiOnsiY29udGVudCI6Ik1FWUNJUURhRFZvSkFxQ1BvK2xzUGRzWUdiaTQzNVlsWlRqWW5rRzJiQlhMS0xONDZ3SWhBSjRIV3VqbkRZWHp5TWJYMDJNd0hTR2JmeUNMUGYycUpJWTJHWExaTjZDOCIsInB1YmxpY0tleSI6eyJjb250ZW50IjoiTFMwdExTMUNSVWRKVGlCRFJWSlVTVVpKUTBGVVJTMHRMUzB0Q2sxSlNVTXhha05EUVd3eVowRjNTVUpCWjBsVlVEaDBhVFJwZEdneVJVbFhNbEJXZG5oTk1HNW5URzVKWkVGM2QwTm5XVWxMYjFwSmVtb3dSVUYzVFhjS1RucEZWazFDVFVkQk1WVkZRMmhOVFdNeWJHNWpNMUoyWTIxVmRWcEhWakpOVWpSM1NFRlpSRlpSVVVSRmVGWjZZVmRrZW1SSE9YbGFVekZ3WW01U2JBcGpiVEZzV2tkc2FHUkhWWGRJYUdOT1RXcFZkMDFVU1RWTlJFa3dUbFJKTkZkb1kwNU5hbFYzVFZSSk5VMUVTVEZPVkVrMFYycEJRVTFHYTNkRmQxbElDa3R2V2tsNmFqQkRRVkZaU1V0dldrbDZhakJFUVZGalJGRm5RVVZLWVdWSlRVcDRjRlV6YWxGb2MzaFRaVFJ2VldFeFNHWkJjSGhhTkRKYWRXbEVjVEFLWm5OT1IwcERSVEpLYUcxRVRYSmlWRmhDVUVSSmFETlBWRXhCVEZaRWFIUnJWbU5rU1N0aGJIZ3pXRFk1U205c0syRlBRMEZZZDNkblowWTBUVUUwUndwQk1WVmtSSGRGUWk5M1VVVkJkMGxJWjBSQlZFSm5UbFpJVTFWRlJFUkJTMEpuWjNKQ1owVkdRbEZqUkVGNlFXUkNaMDVXU0ZFMFJVWm5VVlUwV1U5NENtSjFhR1JRU1RWUVdWaEdkM1J5VEZwUE1FdGhWMWh6ZDBoM1dVUldVakJxUWtKbmQwWnZRVlV6T1ZCd2VqRlphMFZhWWpWeFRtcHdTMFpYYVhocE5Ga0tXa1E0ZDB0M1dVUldVakJTUVZGSUwwSkRSWGRJTkVWa1drZHNkR0ZZVW5saFV6VnpXbGRTY21JeldrRlpNbWhvWVZjMWJtUlhSbmxhUXpWcldsaFpkd3BMVVZsTFMzZFpRa0pCUjBSMmVrRkNRVkZSWW1GSVVqQmpTRTAyVEhrNWFGa3lUblprVnpVd1kzazFibUl5T1c1aVIxVjFXVEk1ZEUxRGMwZERhWE5IQ2tGUlVVSm5OemgzUVZGblJVaFJkMkpoU0ZJd1kwaE5Oa3g1T1doWk1rNTJaRmMxTUdONU5XNWlNamx1WWtkVmRWa3lPWFJOU1VkTVFtZHZja0puUlVVS1FXUmFOVUZuVVVOQ1NEQkZaWGRDTlVGSVkwRXpWREIzWVhOaVNFVlVTbXBIVWpSamJWZGpNMEZ4U2t0WWNtcGxVRXN6TDJnMGNIbG5Remh3TjI4MFFRcEJRVWRWY2k5TlMyTkJRVUZDUVUxQlUwUkNSMEZwUlVGMFRHUkVhbTgwT0hsNWNVMXlSVmhvYVRCbVIybHJZMk5FVTNKaVdEUmtZakZpWkhGdE5qVkRDa2RoYjBOSlVVTllkRTVGU1NzdkszQnVjRmN6VWxCbFRIcFdObk5KWWxwNmFuazJjVEZsWVRCVGN6TlphSG8xZFhONlFVdENaMmR4YUd0cVQxQlJVVVFLUVhkT2JrRkVRbXRCYWtKcU5HRlJORVp0VVhCalRUVXJLM2x5VFdKQlVVcElZWHB0Ynl0TU5EWmtUMUZ4UzFsM2VsZzFTV1pDU3pWM1NtNHZiRTg1U0FvMk4wSXlPVTloWTBoS1JVTk5RMDUzTkUxWVkyUXZjRlpZY1VodlduQkdNVTlTZWtveWRteEdkbFJVTVRsUlltdFpVMG96TmtwSmMwcExZbFZuZVVsdENubzRSMHRuVGxjMlUzTjJWMlJuUFQwS0xTMHRMUzFGVGtRZ1EwVlNWRWxHU1VOQlZFVXRMUzB0TFFvPSJ9fX19",
"integratedTime": 1738118728,
"logID": "c0d23d6ad406973f9559f3ba2d1ca01f84147d8ffc5b8445c224f98b9591801d",
"logIndex": 166475237,
"verification": {
"inclusionProof": {
"checkpoint": "rekor.sigstore.dev - 1193050959916656506\n44571043\nYpguzhfi7pqJHenhqbV/DZSoBVT6BotILrTG6wvQRr4=\n\n— rekor.sigstore.dev wNI9ajBFAiEAyB6z386aVU4Pdrv7/E93Zj2Ff+d4l5CuWsekNX3l1qgCIBlVF0CYoRtdj/b+9T3Ol8W9UCF0UevVpG8lRj+p0GR7\n",
"hashes": [
"b1227726b0dcda249faf46865e64a201c76ad454b479b49986685f01fd051ac9",
"16e051490976ed0f29b3540503e3ec2d1e624506ccbd4e1f2af8d0d65fe78576",
"0ff7998209725f2054b711868343f93ded93190dd67ad931e719c52ed970f47e",
"511b4d734ff81314ecc352594650d9b45ec5982ef195bd8eca6582e485924a9a",
"094b6948953f86d5dd0c0816fa656cda71e9525ed359fcf6d1b9abaafbb04ec7",
"ab7765184b127493d778473bbbb6cc93ce7ffcf48d56bc9f7adb7794ec25ec36",
"f406d63fcea8fdeaacd309b325744b9e06998c90d850ea83e052a27ff580dcf8",
"19603543f01fe4cda6809e0753b90374277c7100fc6364667c75e14ff79f69df",
"1977c766f3914c7010c2c3184786f2447bf6966f3957d3694914aad43d2f357b",
"5d583e97d8862c0d76fa63464f926a941765680a743443bd514155b0b2b60803",
"e5e4fad74b8c343b078ef744fe6fbe300a8ab8019fabe11bfee4ac951eff53f5",
"83139f140f21760bf8d794c28870212b29d59871263393773d68843262def5fa",
"5980b2c649b79cbb8de8cb9b06218663d6794ebcbf33882588724aed5328ed5e",
"8d4f7eb608d320a51819e53b4fb463ab22fe17e80557db427705f6199d54b50b",
"bde9b268c8f435ad4b3236c1ffd0e692af13fa301bde8fb20844a001ac940015"
],
"logIndex": 44570975,
"rootHash": "62982ece17e2ee9a891de9e1a9b57f0d94a80554fa068b482eb4c6eb0bd046be",
"treeSize": 44571043
},
"signedEntryTimestamp": "MEQCIGYWF+PJ9Fjg+MLuuws61PgXuyovq4AKspCczHEcgtvWAiAaU/kA71lACBXGxbqBt8URijZwAzbfWGSwwAsi90bTGw=="
}
}
Loading