Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Reuse Fulcio cert #46

Open
imjasonh opened this issue Jun 29, 2023 · 1 comment
Open

Reuse Fulcio cert #46

imjasonh opened this issue Jun 29, 2023 · 1 comment

Comments

@imjasonh
Copy link
Member

Today we request a new Fulcio cert for each thing we sign or attest, which can become a lot.

Instead we should cache a Fulcio cert for some duration (5 minutes) and reuse it for all signings done during that time. The details of the cert (identity, GH workflow ID, etc.) will be identical for all the certs, it'll just mean a lot less traffic and latency talking to Fulcio.

@jonjohnsonjr
Copy link
Collaborator

Started on something for attest: https://github.com/jonjohnsonjr/secant

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants