Chainloop
By integrating Chainloop with EJBCA and SignServer, you get an end-to-end solution that will create in-toto attestations signed with SignServer and EJBCA, stored in an OCI registry.
This allows you to:
Build secure devices with PKI
Secure connected vehicles and V2X infrastructure
Ensure devices are safe and secure by design
Secure modern 5G networks and infrastructure
Protect critical IIoT and OT infrastructure
Build trusted and Matter-compliant IoT devices
Avoid costly downtime and disruption
Replace legacy CA infrastructure with modern PKI
Keep up with DevOps teams and CI/CD pipelines
Secure every device and workload with an identity
Stay ahead of threats and prepare for post-quantum
Chainloop is an open-source evidence store for software supply chain attestations, Software Bill of Materials (SBOMs), vulnerability reports (VEX), SARIF, CSAF files, QA reports, and more.
APPLICATION TYPE:
By integrating Chainloop with EJBCA and SignServer, you get an end-to-end solution that will create in-toto attestations signed with SignServer and EJBCA, stored in an OCI registry.
This allows you to:
Use Keyfactor’s SignServer for secure, widely adopted, enterprise-grade attestation signing.
Access EJBCA’s comprehensive certificate management system, which is trusted by enterprises worldwide.
Enjoy added trust and security with minimal setup, whether you’re using Chainloop Open Source or the Chainloop Platform.
Enterprise Verified
Local Signing of Attestations with Chainloop and EJBCA Ephemeral Certificates
With this integration, Chainloop can be configured to generate short-lived signing certificates by using EJBCA as the certificate authority (CA), enabling a user experience similar to Sigstore Fulcio’s “keyless” approach.
Resources:
Remote Signing of Attestations using Chainloop and SignServer
This integration allows users to send the attestation payload to a SignServer worker before sending it to Chainloop for storage.
Resources:
Local Signing of Attestations with Chainloop and EJBCA Ephemeral Certificates
With this integration, Chainloop can be configured to generate short-lived signing certificates by using EJBCA as the certificate authority (CA), enabling a user experience similar to Sigstore Fulcio’s “keyless” approach.
Resources:
Remote Signing of Attestations using Chainloop and SignServer
This integration allows users to send the attestation payload to a SignServer worker before sending it to Chainloop for storage.
Resources: