2026-06-15 –, Opal
A successful build is only the beginning of an artifact’s journey to a user’s device. Before it can be shipped, it needs to be digitally signed so that users can be certain it’s been built by Fedora. In this talk, we'll cover how signing works in Fedora, and why it's time to upgrade our infrastructure.
The talk will begin with an introduction to the content we have historically signed, content we’d like to sign in the future, and why.
We will then examine Sigul, the signing service Fedora has used for many years. The service design will be covered, and how it works within Fedora’s infrastructure to sign various build artifacts. We’ll step through the flow for a few common artifact types like RPMs and UEFI applications.
The next portion of the talk will cover Siguldry, a new signing service that is heavily inspired by Sigul. The architecture will be compared with Sigul and differences will be highlighted and explained. We’ll also go over what new features people can expect, including support for RPM v6 signature features, post-quantum cryptography, signatures for use with Cosign, and more.
Attendees should come away from the talk with a good understanding of the signing process, the projects involved, and how to contribute to it to ensure it remains in good working order.
I work at Microsoft on the Linux Community Engineering team with a focus on Fedora.
I've worked on various Fedora infrastructure tools and projects. Most recently I've focused on signing services and tools to push images we build to popular public clouds. Previously I worked on infrastructure tools like fedora-messaging, release-monitoring.org, and bodhi. I also spent some time as a Fedora kernel maintainer.