Improve Errors and Update Readme #16
Merged
Chainguard Enforce / Enforce - Commit Signing
required action
Jan 17, 2024 in 0s
Failed to verify commit signature.
CLAIM | DESCRIPTION | |
---|---|---|
✅ | Found Git signature | |
✅ | Validated Git signature | |
✅ | Validated Rekor entry | |
❌ | Allowed by policy | 1 error occurred: |
* none of the expected identities matched what was in the certificate, got subjects [[email protected]] with issuer https://accounts.google.com | ||
Details
Error Details
user policy verification failed: 1 error occurred:
* none of the expected identities matched what was in the certificate, got subjects [[email protected]] with issuer https://accounts.google.com
Certificate
Certificate:
Data:
Version: 3 (0x2)
Serial Number: 447383542758144601369302592023606268369247407999 (0x4e5d5f33e85bcc6da809ead997a81aa415880f7f)
Signature Algorithm: ECDSA-SHA384
Issuer: O=sigstore.dev,CN=sigstore-intermediate
Validity
Not Before: Jan 17 12:44:05 2024 UTC
Not After : Jan 17 12:54:05 2024 UTC
Subject: Subject Public Key Info:
Public Key Algorithm: ECDSA
Public-Key: (256 bit)
X:
54:28:34:70:7b:c2:b0:ef:ce:ca:fb:d4:59:49:a5:
b0:99:69:5b:1c:6c:c8:a4:2c:9e:c7:24:20:16:0c:
8f:40
Y:
50:0f:cb:8e:56:75:38:c7:32:7d:1d:94:22:ca:df:
0a:34:4e:2d:30:67:7c:d4:72:71:de:f9:63:08:f5:
91:71
Curve: P-256
X509v3 extensions:
X509v3 Key Usage: critical
Digital Signature
X509v3 Extended Key Usage:
Code Signing
X509v3 Subject Key Identifier:
8D:3D:EE:44:59:EB:A3:25:84:32:33:C7:27:57:58:13:DC:C3:DB:8A
X509v3 Authority Key Identifier:
keyid:DF:D3:E9:CF:56:24:11:96:F9:A8:D8:E9:28:55:A2:C6:2E:18:64:3F
X509v3 Subject Alternative Name: critical
email:[email protected]
oidcIssuer:
https://accounts.google.com
Unknown extension 1.3.6.1.4.1.57264.1.8
Signed Certificate Timestamp:
BHkAdwB1AN09MGrGxxEyYxkeHJlnNwKiSl643jyt/4eKcoAvKe6OAAABjRdzQfcAAAQDAEYwRAIgaryH9VhY8HRiEzPhrc1FkwURvTe7TB0RdLr7/11R5XwCIBb1Rpsbb/s2kU1foLL8Tw8ucZbbjz5slzXDCkgD+CkT
Signature Algorithm: ECDSA-SHA384
30:64:02:30:4a:3b:45:36:c0:47:89:a1:25:e2:2c:eb:fc:ca:
8b:55:44:0a:9f:a6:d7:49:80:7e:90:ce:21:4b:14:2c:fb:5e:
52:15:12:16:1f:e5:4b:ea:9a:37:f6:25:ec:09:85:6b:02:30:
3b:b5:bd:93:6e:f4:16:cd:70:3e:82:15:7c:47:70:63:48:ae:
67:98:d8:d3:91:bb:eb:c8:f7:60:22:5e:33:e3:e8:63:c9:41:
c5:8e:6d:60:71:9e:01:69:9d:c1:40:87
Rekor Entry
{
"body": "eyJhcGlWZXJzaW9uIjoiMC4wLjEiLCJraW5kIjoiaGFzaGVkcmVrb3JkIiwic3BlYyI6eyJkYXRhIjp7Imhhc2giOnsiYWxnb3JpdGhtIjoic2hhMjU2IiwidmFsdWUiOiI1MzNiNDVmYmFhZDE4MzgxZDJkMGJlOWM1YmIwOGQwYzBjYjVkZmUzNTQ0OTFjODhmNjQ2NTFlZjRmZDA3MDFiIn19LCJzaWduYXR1cmUiOnsiY29udGVudCI6Ik1FUUNJRnpiZVdPcnd6ZHdNcE1vcmZKN1g1UlB5M1cxUnBhWU9UTUMzaG9yVWJlWUFpQVlpb2NWUzNMbUN2VytPbnhPZm1mdllGbld4b2wrdk0xNmRpWEpDaW1XN0E9PSIsInB1YmxpY0tleSI6eyJjb250ZW50IjoiTFMwdExTMUNSVWRKVGlCRFJWSlVTVVpKUTBGVVJTMHRMUzB0Q2sxSlNVTXdWRU5EUVd4cFowRjNTVUpCWjBsVlZHd3haazByYUdKNlJ6SnZRMlZ5V213MloyRndRbGRKUkRNNGQwTm5XVWxMYjFwSmVtb3dSVUYzVFhjS1RucEZWazFDVFVkQk1WVkZRMmhOVFdNeWJHNWpNMUoyWTIxVmRWcEhWakpOVWpSM1NFRlpSRlpSVVVSRmVGWjZZVmRrZW1SSE9YbGFVekZ3WW01U2JBcGpiVEZzV2tkc2FHUkhWWGRJYUdOT1RXcFJkMDFVUlROTlZFa3dUa1JCTVZkb1kwNU5hbEYzVFZSRk0wMVVTVEZPUkVFeFYycEJRVTFHYTNkRmQxbElDa3R2V2tsNmFqQkRRVkZaU1V0dldrbDZhakJFUVZGalJGRm5RVVZXUTJjd1kwaDJRM05QTDA5NWRuWlZWMVZ0YkhOS2JIQlhlSGh6ZVV0UmMyNXpZMnNLU1VKWlRXb3dRbEZFT0hWUFZtNVZOSGg2U2psSVdsRnBlWFE0UzA1Rk5IUk5SMlE0TVVoS2VETjJiR3BEVUZkU1kyRlBRMEZZWTNkblowWjZUVUUwUndwQk1WVmtSSGRGUWk5M1VVVkJkMGxJWjBSQlZFSm5UbFpJVTFWRlJFUkJTMEpuWjNKQ1owVkdRbEZqUkVGNlFXUkNaMDVXU0ZFMFJVWm5VVlZxVkROMUNsSkdibkp2ZVZkRlRXcFFTRW94WkZsRk9YcEVNalJ2ZDBoM1dVUldVakJxUWtKbmQwWnZRVlV6T1ZCd2VqRlphMFZhWWpWeFRtcHdTMFpYYVhocE5Ga0tXa1E0ZDB0QldVUldVakJTUVZGSUwwSkNOSGRJU1VWaFdrZFdhVmxZVG5Cak1taHBZek5rZWt4dFVteGthMEp1WWxkR2NHSkROV3BpTWpCM1MxRlpTd3BMZDFsQ1FrRkhSSFo2UVVKQlVWRmlZVWhTTUdOSVRUWk1lVGxvV1RKT2RtUlhOVEJqZVRWdVlqSTVibUpIVlhWWk1qbDBUVU56UjBOcGMwZEJVVkZDQ21jM09IZEJVV2RGU0ZGM1ltRklVakJqU0UwMlRIazVhRmt5VG5aa1Z6VXdZM2sxYm1JeU9XNWlSMVYxV1RJNWRFMUpSMHBDWjI5eVFtZEZSVUZrV2pVS1FXZFJRMEpJYzBWbFVVSXpRVWhWUVROVU1IZGhjMkpJUlZSS2FrZFNOR050VjJNelFYRktTMWh5YW1WUVN6TXZhRFJ3ZVdkRE9IQTNielJCUVVGSFRncEdNMDVDT1hkQlFVSkJUVUZTYWtKRlFXbENjWFpKWmpGWFJtcDNaRWRKVkUwclIzUjZWVmRVUWxKSE9VNDNkRTFJVWtZd2RYWjJMMWhXU0d4bVFVbG5Da1oyVmtkdGVIUjJLM3BoVWxSV0syZHpkbmhRUkhrMWVHeDBkVkJRYlhsWVRtTk5TMU5CVURSTFVrMTNRMmRaU1V0dldrbDZhakJGUVhkTlJGcDNRWGNLV2tGSmQxTnFkRVpPYzBKSWFXRkZiRFJwZW5JdlRYRk1WbFZSUzI0MllsaFRXVUlyYTAwMGFGTjRVWE1yTVRWVFJsSkpWMGdyVmt3MmNHOHpPV2xZY3dwRFdWWnlRV3BCTjNSaU1sUmlkbEZYZWxoQksyZG9WamhTTTBKcVUwczFibTFPYWxSclluWnllVkJrWjBsc05IbzBLMmhxZVZWSVJtcHRNV2RqV2pSQ0NtRmFNMEpSU1dNOUNpMHRMUzB0UlU1RUlFTkZVbFJKUmtsRFFWUkZMUzB0TFMwSyJ9fX19",
"integratedTime": 1705495446,
"logID": "c0d23d6ad406973f9559f3ba2d1ca01f84147d8ffc5b8445c224f98b9591801d",
"logIndex": 64309044,
"verification": {
"inclusionProof": {
"checkpoint": "rekor.sigstore.dev - 2605736670972794746\n60160694\ny6Pol6/zVB0fjElNl4AQ3Yh6zoSgNUFFtNNNAHpnsiI=\nTimestamp: 1705499651419699498\n\n— rekor.sigstore.dev wNI9ajBFAiEA4JQ1xlL40yuI2SacH4ztCq1iMk+qO+csztFx/uLEGMMCICBho1HOaAypc1FJh62oU/Sk0GeTKt8Ifo/aqNwNouOT\n",
"hashes": [
"a075e72a4a99670371c42bb49a3af13ca998ccd8322abfc48feced1b29e8298c",
"a37814e8ed82c8abe98cd1c30d56cfb6e1a02f90f41c8b7219cb63b1d9fd7183",
"63f36d6542c708efecdf6ff481e1b134c5be426b062d72cd8cba0af1f8908357",
"34a1233c52ac08d98301ff602106c2a103cde3a6611a1d6d0f8a2e74cf7b3cdf",
"89fbcb9d7ef822e19d91c0bfa227b19d92fb647310f36eaebba674f1daa5c35f",
"792bd0eafb013e27c2e3b964f0ad7e16cb62dfd4aa15ff2dc24a3558d21f3e7b",
"385ed711a8b32c4c089d77bc8f2689592c5ba1c8939a4030a79cc4f35e67f81a",
"505b595ca3987adf5066e1cdb29cef691a26e807f4a67165410b6eeb0029faa7",
"0ea9de927869ff87febb9ddeffe70146c2cc2ce9edcebf6d0078c765ecb43463",
"6d39bfd46b2a35c7b88c9cffb56cc864fc0771d4c00b6a8b4737a73e6be72e1b",
"efe990a510dfb78ed4a9aa52a3b20e6fd25d58fc6269a60e248160fc204616db",
"59b30021cccfd012fe9fcaccff0ef7c4f9046d714822181518dd34abd631f3df",
"de19f351cdada2995eaef5db40003f7d674e1389af5da42bf1f01c97d3f51f6a",
"f6ad9514b504fca60ab3d2aab42078aee7f16fdeb3cd5b67a1279baeb8936bb6",
"eb8f54ce302f3a56b0614aa8f0e26c24a7a9dae766ba09c7b72c2478607ce229",
"fa350cf488b91904868c1a413f9983b23a6297f877e77de27214d50957d9ef28",
"1f4b08f02f68a4087a665eb95f7876e5581f8fd3171192d0939f4dfe32137c02",
"0eb4e5f208da443bfa94dfd56356e6bbcabf7ee2f7bbae5b3fbb8e9208541bc6",
"9f1efda8fe9a51f5e067a3b8e270b53c039f796f14ac326b1385448bbc684556",
"51e5d80682cc50abdb392ed3a0cb1aa1b946e1f4bff103d04d314620155e13bd",
"98c486feb5d87092a78a46c4b5be04868654900affc2e86ffb20074dc73a883a",
"6969c49bd73f19bf28a5eaeabd331ddd60502defb2cd3d96e17b741c80adec6c"
],
"logIndex": 60145613,
"rootHash": "cba3e897aff3541d1f8c494d978010dd887ace84a0354145b4d34d007a67b222",
"treeSize": 60160694
},
"signedEntryTimestamp": "MEUCIEZsYWluviPM87R/rLbdsydomMHlu1FSFaynxunQDF16AiEAu+FKCVPdt5XPIf+a2eZKwAWpDjC8HP5k0xwMIev70fM="
}
}
Loading