Skip to content

rotate a keyholder in v13 #1498

@jku

Description

@jku

Most keyholders have been keyholders since the root-signing system started: it's a good time to start rotating more regularly.

  • During the last signing I believe @dlorenc expressed willingness to step down: Dan, can you confirm if I remember correctly?
  • We've talked to Lance Ball (Red Hat Trusted Artifact Signer engineering manager) already about potentially becoming a keyholder

Assuming both of you are happy with this, my proposal is to remove dan as (root, targets) signer and at the same time add Lance as (root, targets) signer.

Mechanically keyholder changes are approved by the existing keyholders, but obviously this is a community decision: if you have opinions or other suggestions, please leave a comment.

CC @sigstore/sigstore-keyholders

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions