Sign container images using SMCTL
DigiCert® Software Trust Manager supports native container image signing using SMCTL. You can use the simplified signing workflow to sign OCI container images without installing or configuring third-party signing tools or plugins. This workflow enables container signing directly through SMCTL while keeping the signing key managed by Software Trust Manager.
SMCTL supports the following signature formats:
COSE
JWS
OCI (Cosign-compatible)
Note
To sign a container image, use the smctl sign command with the --simple option to sign a container image without using third-party signing tools or libraries.
Ensure that:
SMCTL version 1.7.0 or later is installed and configured.
You are authenticated to Software Trust Manager.
You have access to a Software Trust Manager key pair that can be used for signing.
You have the fully qualified OCI image reference for the container image you want to sign.
Obtain the fully qualified OCI image reference, including the registry, organization, repository, and version.
docker.io/<organization>/<repository>:<version>
For example:
smctl sign --simple \ --input-uri docker.io/<organization>/<repository>:<version>
Identify the Software Trust Manager key pair alias that you want to use to sign the container image.
smctl sign --simple \ --input-uri docker.io/<organization>/<repository>:<version> \ --keypair-alias <STM-keypair-alias> \
Specify one of the following values for --signature-format:
- cose — Creates a COSE Sign1 signature.
- jws — Creates a JWS/Notation signature.
- oci — Creates a Cosign-compatible OCI signature.
Run the commands. For example:
smctl sign --simple \ --input-uri docker.io/<organization>/<repository>:<version> \ --keypair-alias <STM-keypair-alias> \ --signature-format <cose|jws|oci>
SMCTL provides additional options for configuring container signing workflows, including:
Important
The following signing options works only when the signature format is oci (or if the signature format is unspecified, since oci is the default):
--embed-certificate--embed-certificate-chain--oci-annotation--new-bundle-format--upload-tlog--rekor-url--rekor-api-version--rekor-token--rekor-tls-cert--rekor-tls-key--rekor-ca-cert
Command | Description |
|---|---|
| Embed the signing certificate in a Cosign-style signature. Default value is |
| Embed the full certificate chain in a Cosign-style signature. Default value is |
| OCI image reference to sign. |
| Provide the keypair alias to be used for signing. |
| Default value is
|
| OCI image annotation as key=value pair (cosign-style). You can specify this option multiple times. |
| Rekor API version to use. (Default value: v1) |
| CA certificate for Rekor TLS verification. |
| TLS certificate for Rekor client authentication. |
| TLS key for Rekor client authentication. |
| Authentication token for Rekor. |
| Rekor transparency log URL. Default to rekor.sigstore.dev |
| Signature envelope format: cose (pure COSE Sign1), jws (Notation), or oci (Cosign-compatible). Default value is |
| Upload signature to Rekor transparency log (Cosign-style). |
| the COSE-format equivalent of |
| the JWS-format equivalent of |
| signs all images in a multi-arch image, cosign-style (only valid with --signature-format |
| writes the signed payload to a file, equivalent to cosign's --output-payload (only valid with --signature-format |
| registry authentication credentials |
| registry authentication credentials |