Chapter 4. Verifying Red Hat signatures


You can use Red Hat Trusted Artifact Signer (RHTAS) to verify the authenticity of Red Hat’s products, and artificial intelligence (AI) generated Granite models.

Prerequisites

  • Installation of RHTAS running on Red Hat Enterprise Linux or Red Hat OpenShift Container Platform.
  • Access to the Red Hat’s Customer Portal for downloading product signing keys.
  • A workstation with the cosign binary installed, version 2.2 or later.

Procedure

  1. Download Red Hat’s product signing keys from the Customer Portal for the products you want to verify. This downloads a text file containing Red Hat’s public key signature.
  2. Open a terminal on your workstation. Download the Rekor public key, and create a new rekor.pem file:

    $ curl https://REKOR_HOSTNAME/api/v1/log/publicKey > rekor.pem
    Copy to Clipboard Toggle word wrap
  3. Create a new cosign public key from the Red Hat product signing key:

    $ cat 63405576.txt > cosign.pub
    Copy to Clipboard Toggle word wrap
  4. Configure your shell environment for cosign to use the new Rekor public key:

    $ export SIGSTORE_REKOR_PUBLIC_KEY=rekor.pem
    Copy to Clipboard Toggle word wrap
  5. Verify a Red Hat signed image by using the cosign public key:

    cosign verify --key cosign.pub IMAGE_NAME:TAG
    Copy to Clipboard Toggle word wrap
    $ cosign verify --key cosign.pub registry.redhat.io/rhelai1/granite-3.1-8b-starter-v1:latest
    Copy to Clipboard Toggle word wrap
Red Hat logoGithubredditYoutubeTwitter

学习

尝试、购买和销售

社区

关于红帽文档

通过我们的产品和服务,以及可以信赖的内容,帮助红帽用户创新并实现他们的目标。 了解我们当前的更新.

让开源更具包容性

红帽致力于替换我们的代码、文档和 Web 属性中存在问题的语言。欲了解更多详情,请参阅红帽博客.

關於紅帽

我们提供强化的解决方案,使企业能够更轻松地跨平台和环境(从核心数据中心到网络边缘)工作。

Theme

© 2026 Red Hat
返回顶部