ISigstore: Iphrojekthi yokwenza ngcono ukuthengwa kwemithombo evulekile

ISigstore: Iphrojekthi yokwenza ngcono ukuthengwa kwemithombo evulekile

ISigstore: Iphrojekthi yokwenza ngcono ukuthengwa kwemithombo evulekile

Namuhla, sizokhuluma ngakho "I-Sigstore". Enye yezinto eziningi, ze amaphrojekthi wamahhala futhi avulekile ngaphansi kokufundiswa kwe- Isisekelo se-Linux.

"I-Sigstore" Ngokuyisisekelo iphrojekthi eyenzelwe ukuhlinzeka ngemisebenzi enhle yomphakathi engenzi nzuzo, ukuze thuthukisa ukuthengiswa kwempahla de isoftware yomthombo ovulekile kusiza ukwamukelwa kwesiginesha ye-software ye-cryptographic esekelwa ubuchwepheshe bokubhalisa obala.

Izithuthi zeBanga le-Linux

"I-Sigstore", Akuyona yodwa Iphrojekthi yeLinux Foundation esikhulume ngayo ezikhathini ezedlule. Omunye wabo ubelokhu Izithuthi zeBanga le-Linux, esichaza ngaleso sikhathi ngale ndlela elandelayo:

"I-Automotive Grade (Quality) Linux yiphrojekthi yokusebenzisana yomthombo ovulekile ehlanganisa abenzi bezimoto, abathengisi nezinkampani zobuchwepheshe ukusheshisa ukuthuthukiswa nokwamukelwa kwesitaki sesoftware esivuleke ngokuphelele semoto yangomuso. Njengoba iLinux ingumgogodla wayo, i-AGL ithuthukisa ipulatifomu evulekile kusuka phansi kuze kube manje engasebenza njengezinga lomkhakha we-de facto ukunika amandla ukuthuthukiswa okusheshayo kwezici ezintsha nobuchwepheshe." I-Linux Foundation: Yethula ku-Consumer Electronics Show 2020

I-Linux Foundation: Yethula ku-Consumer Electronics Show 2020
I-athikili ehlobene:
I-Linux Foundation: Yethula ku-Consumer Electronics Show 2020
Izithuthi zeBanga le-Linux
I-athikili ehlobene:
I-Linux ishaya umgwaqo ngenxa ye-Automotive Grade Linux

Kamuva, ezincwadini ezizayo sizobhekana namanye amaphrojekthi, kepha kulabo abafisa ukuzihlola ngokwabo, bangakwenza lokhu ngesixhumanisi esilandelayo: Amaphrojekthi weLinux Foundation.

ISigstore: Iphrojekthi yeLinux Foundation

ISigstore: Iphrojekthi yeLinux Foundation

Yini iSigstore?

Ngokusho kwakhe Iwebhusayithi esemthethweni yeSigstore, okufanayo:

"Iphrojekthi eyenziwe ngenhloso yokuhlinzeka ngensizakalo yomphakathi engenzi nzuzo ukwenza ngcono ukuthengwa kwesoftware yomthombo ovulekile ngokusiza ukwamukelwa kwesiginesha ye-software ye-cryptographic, esekelwa ubuchwepheshe bokubhalisa obala. Ngaphezu kwalokho, izama ukuqeqesha abathuthukisi be-software ukuthi basayine ngokuphepha izinto zobuciko zesoftware ezinjengokukhishwa kwamafayela, izithombe zeziqukathi, ama-binaries, isikweletu sezinto ezibonakalayo, nokuningi."

Ngaphezu kwalokho, le phrojekthi ifuna ukuqinisekisa ukuthi:

"Izinto ezisayiniwe zigcinwa kumarekhodi womphakathi angenabufakazi."

Kungani iSigstore ibalulekile?

Le phrojekthi, amathuluzi ayo namalungu, ifuna ukuyigwema «ukuhlaselwa kokuthengwa kwesoftware », njengokuthi, kwenzekeni nge- SolarWinds nezinye ezaziwayo ezikhathini zakamuva.

"AbakwaMicrosoft bathe abaduni basebenzise uhlelo lokuqapha nokuphathwa kweSolarWinds 'Orion, okubavumela ukuthi bazenze noma yimuphi umsebenzisi ne-akhawunti ekhona enhlanganweni, okubandakanya nama-akhawunti anelungelo elikhulu. I-Russia kuthiwa isebenzise izingqimba zezinto ezithengiswayo ukuze ifinyelele ezinhlelweni zikahulumeni."

I-athikili ehlobene:
Ukuqhekeka kweSolarWinds kungaba kubi kakhulu kunalokho obekulindelwe

Kuqondwe ngu «ukuhlaselwa kokuthengwa kwesoftware » esenzweni, isigelekeqe sifaka ikhodi enonya kusoftware esemthethweni ukuyisabalalisa yonke indawo.

Ngakho-ke, amaphrojekthi wamahhala / avulekile akhululekile futhi asebenziseka kalula, njenge "I-Sigstore" zidingeka ngokwengeziwe ezinsukwini zethu.

Ungakuvimbela kanjani ukuhlaselwa kohlelo lokunikezwa kwesoftware?

Yize, kwezinye izikhathi, sinikeze izeluleko zokuphepha ezisebenzisekayo, ezisebenza kuwo wonke umuntu futhi ngazo zonke izikhathi noma ezimweni, amathiphu alandelayo agxile ngqo ekunciphiseni lolu hlobo lokuhlaselwa ngangokunokwenzeka:

Amathiphu Wokuphepha we-IT wawo wonke umuntu nganoma yisiphi isikhathi
I-athikili ehlobene:
Amathiphu Wokuphepha Kwikhompyutha Wawo Wonke Umuntu Noma Kunini, Noma Kuphi
  1. Gcina iqoqo lawo wonke amathuluzi esoftware wakho nowangaphandle, asetshenzisiwe mahhala futhi avulekile, nokuphathelene nokuvaliwe, asetshenziswayo.
  2. Qaphela ubungozi obaziwayo nobuzayo, bazo zonke izinhlelo zokusebenza nezinhlelo ezisetshenzisiwe, ukufaka isicelo ngokushesha okukhulu amabala atholakala ngokusemthethweni.
  3. Hlala unolwazi ngokuphulwa okutholakele noma ukuhlaselwa okwenziwe, ukuba ngumnikazi nabanikezeli besoftware abavela eceleni, ukugwema isimanga esingalindelekile ngalezi zindlela
  4. Susa esikhathini esifishane, lezo zinhlelo, izinsizakalo kanye nezivumelwano ezingase zingasafuneki (zingadingeki) noma zingasebenzi (zingasetshenziswanga).
  5. Hlela futhi usebenzise amasu ahlanganyelwe nezidingo zokuphepha nabahlinzeki bakho be-software, ukunciphisa ubungozi be-IT kubo nezinqubo zakho zokuphepha.
  6. Qalisa ukuhlolwa kwamakhodi njalo. Futhi gcina ukubuyekezwa kokuvikela okubuyekeziwe futhi ushintshe izinqubo zokulawula, ezidingekayo engxenyeni ngayinye yekhodi eyakhiwe noma esetshenzisiwe.
  7. Yenza ukuhlolwa kokungena okujwayelekile ukukhomba izingozi ezingaba khona kungxenyekazi yakho yekhompyutha.
  8. Sebenzisa izinyathelo zokuphepha ze-IT, njengokulawulwa kokufinyelela kanye nokuqinisekiswa kwe-double factor (2FA) ukuvikela izinqubo zokuthuthukisa isoftware.
  9. Qalisa isoftware yezokuphepha enezendlalelo eziningi zokuvikela. Ikakhulukazi ngokumelene nokungena ngaphakathi, amagciwane kanye nama-rasomwares, kujwayelekile kulezi zinsuku.
  10. Gcina uhlelo lwakho lokulondoloza noma lwezehlakalo lusesikhathini, ukuze gcina ngokuphepha idatha ebalulekile yezinhlelo zakho zokusebenza, amasistimu nemisebenzi (izinqubo), futhi ukwazi ukuthola noma yini yazo, ngesikhathi esifushane kakhulu.

Okuningi mayelana neSigstore

Okuningi mayelana I-Sigstore

Ekugcineni, onjiniyela be "I-Sigstore" bachaza kancane ukusebenza kwale phrojekthi ngale ndlela elandelayo:

"I-Sigstore Isebenzisa ubuchwepheshe obukhona be-x509 PKI kanye nokubhaliswa kokubonisa izinto obala. Abasebenzisi bakhiqiza ukhiye wesikhashana we-ephemeral ukhiye besebenzisa amathuluzi amaklayenti we-sigstore. Insizakalo ye-sigstore PKI izobe isinikeza isitifiketi sokusayina esenziwe ngemuva kwesibonelelo se-OpenID sokuxhuma esiphumelelayo. Zonke izitifiketi zirekhodwa kwirejista yokubonisa okusobala kwesitifiketi futhi nezinto zokusayina zesoftware zithunyelwa kubhaliso lokubonisa ngale kwesiginesha."

Okuningi mayelana neSigstore

"Kusetshenziswa amarekhodi obala kungenisa impande yokwethemba ku-akhawunti ye-OpenID yomsebenzisi. Ngakho-ke singaba nesiqinisekiso sokuthi umsebenzisi ofunwayo ubephethe i-akhawunti yomhlinzeki wesevisi ngesikhathi sokusayina. Lapho umsebenzi wokusayina usuqediwe, okhiye bangalahlwa, kususwe noma yisiphi isidingo sokuphathwa kokhiye abengeziwe noma isidingo sokuchithwa noma sokujikeleza."

Ngeminye imininingwane nge "I-Sigstore" ungavakashela i- iwebhusayithi esemthethweni ku-GitHub kanye nalo Umphakathi (Iqembu) umphakathi cishe -Google.

Isifinyezo: Izincwadi ezahlukahlukene

Isifingqo

Siyethemba lokhu "okuthunyelwe okuwusizo okuncane" cishe  «Sigstore», iphrojekthi ethokozisayo newusizo ye Isisekelo se-Linuxokuyinto a insizakalo yokubonisa ngale kanye nesiginesha yesoftware okuhle komphakathi nokungenzi nzuzo, okwenzelwe i- thuthukisa ukuthengiswa kwempahla isoftware yomthombo ovulekile; inentshisekelo enkulu futhi iyasiza, kuyo yonke «Comunidad de Software Libre y Código Abierto» kanye negalelo elikhulu ekusabalalisweni kwemvelo emangalisayo, enkulu futhi ekhulayo yezicelo ze «GNU/Linux».

Okwamanje, uma ukuthandile lokhu publicación, Ungami yabelana ngayo nabanye, kumawebhusayithi wakho owathandayo, iziteshi, amaqembu noma imiphakathi yokuxhumana nabantu noma amasistimu wokuthumela imiyalezo, okungcono mahhala, okuvulekile kanye / noma okuphephe kakhulu njenge yocingoIsignaliI-mastodon noma enye ye- I-Fediverse, okungcono.

Futhi khumbula ukuvakashela ikhasi lethu lasekhaya ku- «DesdeLinux» ukuhlola izindaba eziningi, kanye nokujoyina isiteshi sethu esisemthethweni se- I-Telegram ye DesdeLinuxNgenkathi, ukuthola eminye imininingwane, ungavakashela noma yikuphi Umtapo wolwazi oku-inthanethi njengoba I-OpenLibra y I-JedIT, ukufinyelela nokufunda izincwadi zedijithali (ama-PDF) ngalesi sihloko noma ezinye.


Shiya umbono wakho

Ikheli lakho le ngeke ishicilelwe. Ezidingekayo ibhalwe nge *

*

*

  1. Ubhekele imininingwane: Miguel Ángel Gatón
  2. Inhloso yedatha: Lawula Ugaxekile, ukuphathwa kwamazwana.
  3. Ukusemthethweni: Imvume yakho
  4. Ukuxhumana kwemininingwane: Imininingwane ngeke idluliselwe kubantu besithathu ngaphandle kwesibopho esisemthethweni.
  5. Isitoreji sedatha: Idatabase ebanjwe yi-Occentus Networks (EU)
  6. Amalungelo: Nganoma yisiphi isikhathi ungakhawulela, uthole futhi ususe imininingwane yakho.