Microsoft announces Signing Transparency, a cloud service that creates tamper-evident records of software signatures using an append-only ledger backed by confidential computing. The service countersigns COSE envelopes and stores them in an immutable Merkle tree, issuing cryptographic receipts for independent verification. This enables organizations to detect unauthorized releases, verify software authenticity without relying solely on vendors, and maintain audit trails for compliance. The technology addresses supply chain attacks by making any misuse of signing keys visible in public logs, extending Zero Trust principles to software distribution.

7m read timeFrom azure.microsoft.com
Post cover image
Table of contents
Need for transparency in the software supply chainWhat is Microsoft’s Signing Transparency?How Signing Transparency enhances security and trustWhy verifiable code integrity and transparency are essential for software supply chain security

Sort: