Warning: Undefined array key "HTTP_ACCEPT_LANGUAGE" in /home/u596154002/domains/usbusinessreviews.com/public_html/wp-includes/load.php on line 2057

Notice: Function _load_textdomain_just_in_time was called incorrectly. Translation loading for the rank-math domain was triggered too early. This is usually an indicator for some code in the plugin or theme running too early. Translations should be loaded at the init action or later. Please see Debugging in WordPress for more information. (This message was added in version 6.7.0.) in /home/u596154002/domains/usbusinessreviews.com/public_html/wp-includes/functions.php on line 6114
New cryptographic protocol aims to bolster open-source software security - Best Business Review Site 2024

New cryptographic protocol aims to bolster open-source software security

[ad_1]

cybersecurity key

matejmo/Getty Images

BastionZero‘s OpenPubkey, which is a new cryptographic protocol that’s designed to fortify the open-source software ecosystem, is now a Linux Foundation open-source project. Docker is also integrating OpenPubkey, so that you can use it for container signing. This innovative cryptographic technology promises enhanced security through zero-trust passwordless authentication.

OpenPubkey provides this authentication by making a client-side modification to OpenID Connect. Connect is an authentication protocol based on the OAuth 2.0 framework. Together, these technologies simplify how programmers can verify a user’s identity. The OpenID Token can then be committed to a user-held public key. This key transforms an ID Token into a certificate that cryptographically binds an OpenID Connect identity to a public key. 

Also: The best VPN services (and how to choose the right one for you)

This “PK Token” can then be used to sign messages, and these signatures can be authenticated and attributed to the user’s OpenID Connect identity. Essentially, OpenPubkey transforms an OpenID Connect Identity Provider (IdP) into a Certificate Authority (CA)

This process makes any application using OpenID Connect for authentication much more secure without any other changes. OpenPubkey is transparent to users and OpenID providers. An OpenID provider can not even determine that OpenPubkey is being used. This makes OpenPubkey fully compatible with existing OpenID providers. This compatability includes Google, Azure/Microsoft, Okta, OneLogin, and Keycloak. This project is not adding any new OpenID Connect trusted parties.

OpenPubkey is already being used to authenticate signed messages and identities for users with accounts on Google, Microsoft, Okta, and OneLogin. By augmenting OpenID Connect, OpenSubkey will enable users and workloads to sign artifacts under their OpenID identity. This capability is instrumental for applications requiring secure remote access and software supply chain security features, including signed builds, deployments, and code commits.

That level of application all sounds good in practise, but you should keep in mind that even OpenPubkey’s reference implementation is a work in progress. For example, the OpenPubkey client still needs support for the Github OpenID Provider, the Azure OpenID Provider (OP).

Also: The best VPN services for iPhone and iPad (yes, you need to use one)

Jim Zemlin, the Linux Foundation’s executive director, is enthusiastic about hosting the OpenPubkey Project: “This initiative is poised to be a cornerstone in enhancing the security fabric of the open-source software community.” Zemlin extended an invitation to developers and organizations to join hands in this collaborative venture aimed at amplifying software supply chain security.

TestifySec, a prominent cybersecurity player. has endorsed the initiative. Cole Kennedy, CEO of TestifySec, commended the OpenPubkey approach of enabling easy and reliable signing: “The collaboration between Docker and BastionZero has our unwavering support. We are optimistic about the immense benefits the broader community stands to gain.” 

Also: The best VPNs for streaming your favorite shows and sports

Interested in learning more about getting OpenPubkey ready for production? Check out the OpenPubkey GitHub page and get to work. This is an authentication and security project that shows a lot of promise. 



[ad_2]

Source link

slot gacor slot gacor togel macau slot hoki bandar togel slot dana slot mahjong link slot link slot777 slot gampang maxwin slot hoki slot mahjong slot maxwin slot mpo slot777 slot toto slot toto situs toto toto slot situs toto situs toto situs toto situs toto slot88 toto slot slot gacor thailand slot bet receh situs toto situs toto slot toto slot situs toto situs toto situs toto situs togel macau toto slot slot demo slot pulsa slot pragmatic situs toto deposit dana 10k surga slot toto slot link situs toto situs toto slot situs toto situs toto slot777 slot gacor situs toto slot slot pulsa 10k toto togel situs toto slot situs toto slot gacor terpercaya slot dana slot gacor pay4d agen sbobet kedai168 kedai168 deposit pulsa situs toto slot pulsa situs toto slot pulsa situs toto situs toto situs toto slot dana toto slot situs toto slot pulsa toto slot situs toto slot pulsa situs toto situs toto situs toto toto slot toto slot slot toto akun pro maxwin situs toto slot gacor maxwin slot gacor maxwin situs toto slot slot depo 10k toto slot toto slot situs toto situs toto toto slot toto slot toto slot toto togel slot toto togel situs toto situs toto toto slot slot gacor slot gacor slot gacor situs toto situs toto cytotec toto slot situs toto situs toto toto slot situs toto situs toto slot gacor maxwin slot gacor maxwin link slot 10k slot gacor maxwin slot gacor slot pulsa situs slot 10k slot 10k toto slot toto slot situs toto situs toto situs toto bandar togel 4d toto slot