Identity & Access

Linux Foundation Announces OpenPubkey Open Source Cryptographic Protocol

The Linux Foundation has announced OpenPubkey, an open source cryptographic protocol that should help boost supply chain security. 

The Linux Foundation has announced OpenPubkey, an open source cryptographic protocol that should help boost supply chain security. 

The Linux Foundation on Wednesday announced OpenPubkey, an open source cryptographic protocol that should help boost supply chain security. 

OpenPubkey was developed as part of BastionZero’s zero trust infrastructure access product and is now being integrated with Docker. 

OpenPubkey is designed to enable binding crypto keys to users and workloads by turning an OpenID Connect identity provider into a certificate authority. Its goal is to provide enhanced passwordless authentication. 

“This new cryptographic protocol empowers developers to build out software supply chain or security applications. OpenPubkey augments OpenID Connect to enable workloads and users to sign artifacts under their OpenID identity,” the Linux Foundation explained. 

“These keys can be used to cryptographically sign statements, enabling applications such as secure remote access or software supply chain security features such as signed builds, deployments, and code commits,” it added.

The project’s developers noted that OpenPubkey is compatible with existing OpenID providers, including Microsoft, Google, Okta, Keycloak and OneLogin, and it does not require any changes to the provider. 

The GitHub page set up for OpenPubkey provides the reference implementation source code and additional information. 

Related: Silverfort Open Sources Lateral Movement Detection Tool

Advertisement. Scroll to continue reading.

Related: Google Open Sources Binary File Comparison Tool BinDiff

Related: OT/IoT and OpenTitan, an Open Source Silicon Root of Trust

Related: CISA Releases Open Source Software Security Roadmap

Related Content

Data Breaches

The US government issues a red-alert for what appears to be a massive supply chain breach at Sisense, a company that sells big-data analytics...

Supply Chain Security

The discovery of the XZ Utils backdoor reminds an F-Droid developer of a similar incident that occurred a few years ago.

Funding/M&A

Los Angeles firmware and software supply chain firm banks $10.5 million in seed-stage funding led by Two Bear Capital.

Malware & Threats

Multiple Python developers get infected after downloading malware-packed clone of the popular tool Colorama.

ICS/OT

Software risk management firm Finite State has raised a $20 million growth round led by Energy Impact Partners (EIP).

Supply Chain Security

Join the fully immersive virtual event us as we explore the critical nature of software and vendor supply chain security issues. (Login Now)

Cloud Security

The CloudGrappler open source tool can detect the presence of known threat actors in cloud environments.

Application Security

Concluding a two-day OSS security summit, CISA details key actions to help improve open source security.

Copyright © 2024 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version