/home/mukul/cosign>./test/e2e_test_attach.sh + go build -o cosign ./cmd/cosign ++ mktemp -d -t cosign-e2e-attach.XXXX + tmp=/tmp/cosign-e2e-attach.fvPs + cp cosign /tmp/cosign-e2e-attach.fvPs/ + cp ./test/testdata/test_attach_private_key /tmp/cosign-e2e-attach.fvPs/private_key + cp ./test/testdata/test_attach_leafcert.pem /tmp/cosign-e2e-attach.fvPs/leafcert.pem + cp ./test/testdata/test_attach_certchain.pem /tmp/cosign-e2e-attach.fvPs/certchain.pem + cp ./test/testdata/test_attach_rootcert.pem /tmp/cosign-e2e-attach.fvPs/rootcert.pem + cp ./test/testdata/test_attach_second_private_key /tmp/cosign-e2e-attach.fvPs/secondprivate_key + cp ./test/testdata/test_attach_second_leafcert.pem /tmp/cosign-e2e-attach.fvPs/secondleafcert.pem + cp ./test/testdata/test_attach_second_certchain.pem /tmp/cosign-e2e-attach.fvPs/secondcertchain.pem + cp ./test/testdata/test_attach_second_rootcert.pem /tmp/cosign-e2e-attach.fvPs/secondrootcert.pem + pushd /tmp/cosign-e2e-attach.fvPs /tmp/cosign-e2e-attach.fvPs ~/cosign + pass=5642 + export COSIGN_PASSWORD=5642 + COSIGN_PASSWORD=5642 + SRC_IMAGE=busybox ++ crane digest busybox + SRC_DIGEST=sha256:ba76950ac9eaa407512c9d859cea48114eeff8a6f12ebaa5d32ce79d4a017dd8 ++ uuidgen ++ head -c 8 ++ tr A-Z a-z + IMAGE_URI=ttl.sh/cosign-ci/50d163ff + crane cp busybox@sha256:ba76950ac9eaa407512c9d859cea48114eeff8a6f12ebaa5d32ce79d4a017dd8 ttl.sh/cosign-ci/50d163ff:1h 2024/01/18 16:30:42 Copying from busybox@sha256:ba76950ac9eaa407512c9d859cea48114eeff8a6f12ebaa5d32ce79d4a017dd8 to ttl.sh/cosign-ci/50d163ff:1h 2024/01/18 16:30:51 pushed blob: sha256:9211bbaa0dbd68fed073065eb9f0a6ed00a75090a9235eca2554c62d1e75c58f 2024/01/18 16:30:59 pushed blob: sha256:a307d6ecc6205dfa11d2874af9adb7e3fc244a429e00e8e3df90534d4cf0f3f8 2024/01/18 16:30:59 ttl.sh/cosign-ci/50d163ff@sha256:cca7bbfb3cd4dc1022f00cee78c51aa46ecc3141188f0dd520978a620697e7ad: digest: sha256:cca7bbfb3cd4dc1022f00cee78c51aa46ecc3141188f0dd520978a620697e7ad size: 858 2024/01/18 16:31:08 pushed blob: sha256:cd71104276b5df9a5266553e3a9c0ee1cbf82e24e497062865dbba67567c5a36 2024/01/18 16:31:08 pushed blob: sha256:6578a780024e46030c54c696e38b6a3d43f37cf797a7eb600dc872ee00270f9b 2024/01/18 16:31:08 pushed blob: sha256:4f44c251d2bb14be334c8ffe92e0ac4bc67c7be599b6f221f8df6baa3b2fb171 2024/01/18 16:31:08 ttl.sh/cosign-ci/50d163ff@sha256:5d71bd16ab959b8bd1de01fd38c252389e9c3419111c85ce86f6f8b6da50c37f: digest: sha256:5d71bd16ab959b8bd1de01fd38c252389e9c3419111c85ce86f6f8b6da50c37f size: 837 2024/01/18 16:31:14 pushed blob: sha256:34da36df1d0b6a9e1ad85b3f5cdf4d0b117e2ea7eef31b9eba40bfb4a28f245a 2024/01/18 16:31:18 pushed blob: sha256:b2feb76e1f3e03a3ec217930593bc8654d446f89c2096c5a324b8d4a183b87bb 2024/01/18 16:31:18 ttl.sh/cosign-ci/50d163ff@sha256:7108255e7587de598006abe3718f950f2dca232f549e9597705d26b89b7e7199: digest: sha256:7108255e7587de598006abe3718f950f2dca232f549e9597705d26b89b7e7199 size: 858 2024/01/18 16:31:23 pushed blob: sha256:77934dc7d10410a673335b787dd43af18824d4dedc07b16c09826b03dfd688fd 2024/01/18 16:31:23 pushed blob: sha256:69d85f93eb148987834d3929169139a1d2e7c4f12fee441490e3e0aff7d3d720 2024/01/18 16:31:23 ttl.sh/cosign-ci/50d163ff@sha256:59bbc684348b24f4ac886201bb82227b1bb7ac31a53e9a3be90494b6c88772c1: digest: sha256:59bbc684348b24f4ac886201bb82227b1bb7ac31a53e9a3be90494b6c88772c1 size: 566 2024/01/18 16:31:29 pushed blob: sha256:152ad44f30ccf12a8a011f685c6007d5a1290a94b00d470f3506fecfae51c48e 2024/01/18 16:31:31 pushed blob: sha256:b54f1bce6cdb68bb05685f65270b646b929e6b09040f50a4fe6125e198124c1a 2024/01/18 16:31:32 ttl.sh/cosign-ci/50d163ff@sha256:aa5c8091b2938e2d99fcdcc1a4126448c379415e43e06c6c808b8fe203c53937: digest: sha256:aa5c8091b2938e2d99fcdcc1a4126448c379415e43e06c6c808b8fe203c53937 size: 855 2024/01/18 16:31:37 pushed blob: sha256:8f0c0e2eaf488b0f0f64199eb0c42e078c029ad4afc33087bdc6c5e0b222d6ef 2024/01/18 16:31:37 pushed blob: sha256:d00a313d552775357b46c4566a0ba5cc1ae4b656772f313e94e83e9800db3d5d 2024/01/18 16:31:37 ttl.sh/cosign-ci/50d163ff@sha256:d0457b0a00953f8585f7b26da07f728fc9fa1c685053d700e766f75293481dee: digest: sha256:d0457b0a00953f8585f7b26da07f728fc9fa1c685053d700e766f75293481dee size: 566 2024/01/18 16:31:43 pushed blob: sha256:27bef48b3b147114b262a79f7cb390f16e8bf29a0e1ec19c73ea30dae8b5354b 2024/01/18 16:31:48 pushed blob: sha256:8df4bf9de8d8b8ef9f1931a910de2d79b846de2298c246f9282df16a37246b07 2024/01/18 16:31:48 ttl.sh/cosign-ci/50d163ff@sha256:e5005039b8217d8f61b8bc54a4d5bb90e5a9656ac215c73ceabccc48187d6f3f: digest: sha256:e5005039b8217d8f61b8bc54a4d5bb90e5a9656ac215c73ceabccc48187d6f3f size: 858 2024/01/18 16:31:54 pushed blob: sha256:4278c31ab55e6e5e9b44550171609122d8e502cfa44b80e03414ae4ec127ef2c 2024/01/18 16:31:54 pushed blob: sha256:59d87d8e5ca2c8e55b4b52490871831608dcd42d08218bba8c8d2f6a15853b23 2024/01/18 16:31:54 pushed blob: sha256:83d427d3707541604e126dfed6b3eb1d133de1ebaf3e47c650b202f01f650d4c 2024/01/18 16:31:54 ttl.sh/cosign-ci/50d163ff@sha256:023494444241be6beece3230830860e2a50549163533e0502e98df3594a87f9f: digest: sha256:023494444241be6beece3230830860e2a50549163533e0502e98df3594a87f9f size: 837 2024/01/18 16:32:00 pushed blob: sha256:23466caa55cb731e1404a17c8a35ac202c16cb952ff210d4ed50a7518b9e9559 2024/01/18 16:32:07 pushed blob: sha256:29f4353257d60714f1620f68279c2edd71eb4c462215052410ad03c8e781e157 2024/01/18 16:32:07 ttl.sh/cosign-ci/50d163ff@sha256:a4ca727b12c67a0d6a0e8aa578b00eff94a2c092352e24db577aada1536f6c91: digest: sha256:a4ca727b12c67a0d6a0e8aa578b00eff94a2c092352e24db577aada1536f6c91 size: 858 2024/01/18 16:32:12 pushed blob: sha256:ed534eb0ac50b77f23c86ba0f1dd75bff6f3263d90fd99892ba014f338adcf10 2024/01/18 16:32:12 pushed blob: sha256:25ba58d2e06ab46bc458c49d17b9aa86fcf506e81f032768444ff0f8924b1e91 2024/01/18 16:32:12 pushed blob: sha256:eea732db070a649ab8bbc85cf62dce741a4eb994060bc159143a7785506dd657 2024/01/18 16:32:13 ttl.sh/cosign-ci/50d163ff@sha256:cf015a439fe3c3f8e8715bbd449aa72ef2bf06d120179ddc3e726f8dc0956cd7: digest: sha256:cf015a439fe3c3f8e8715bbd449aa72ef2bf06d120179ddc3e726f8dc0956cd7 size: 837 2024/01/18 16:32:19 pushed blob: sha256:b53bc8a95dec7c6c6844eadefaaeea905f63bbb999eb0f95041145e664b7f5c2 2024/01/18 16:32:24 pushed blob: sha256:6e3110d94474bb9c9799103c1d5fcba4e87c5a6264c92debd4d5811ae661bf3e 2024/01/18 16:32:25 ttl.sh/cosign-ci/50d163ff@sha256:8b4700b29069264d0c5b9f7573aeeb94c5f295f07a1e887ef6fe4219b0317e70: digest: sha256:8b4700b29069264d0c5b9f7573aeeb94c5f295f07a1e887ef6fe4219b0317e70 size: 858 2024/01/18 16:32:30 pushed blob: sha256:2be86ca00982a5385221ab4bba6a358d169d7359d6fbe2417034c900457007ae 2024/01/18 16:32:30 pushed blob: sha256:f618917bd5b1eb7a74c2f5b36ab103779ad533f58e557d5e596151c9eface805 2024/01/18 16:32:31 ttl.sh/cosign-ci/50d163ff@sha256:aa708843ce48277acee782c29146fd726132e3027ad689169119aea682d39e78: digest: sha256:aa708843ce48277acee782c29146fd726132e3027ad689169119aea682d39e78 size: 566 2024/01/18 16:32:36 pushed blob: sha256:5aa5b57b77c17dbcb46320c6e2d22020ea442199c1d401afa59658c7c8fa0d74 2024/01/18 16:32:41 pushed blob: sha256:7eec495289aa29dcd011719336480d38619e813d062b7e96e25fa7b4f20a139e 2024/01/18 16:32:41 ttl.sh/cosign-ci/50d163ff@sha256:9cf6c74cf50c04fab4614560c3654d94820c5be0b521dcba79e7bcaba83e4662: digest: sha256:9cf6c74cf50c04fab4614560c3654d94820c5be0b521dcba79e7bcaba83e4662 size: 858 2024/01/18 16:32:46 pushed blob: sha256:2361c3f9931de05f6ed96e4dad9b3a90e06a31d4be451c6987d94259f2f54e72 2024/01/18 16:32:46 pushed blob: sha256:471984ac25dd8bfa575ea70c8edf51e19c3e46195e1edf1e3679c1a58dd23313 2024/01/18 16:32:47 ttl.sh/cosign-ci/50d163ff@sha256:672fe015ea0e45af50c0dbb28322ca6244e933fa0373c6d4acbf77d58594a770: digest: sha256:672fe015ea0e45af50c0dbb28322ca6244e933fa0373c6d4acbf77d58594a770 size: 566 2024/01/18 16:32:53 pushed blob: sha256:2a6e4c3c118c77aa39235be9ffa2b3957265bb88ad7dd51b4811028a3e62389e 2024/01/18 16:33:03 pushed blob: sha256:34af618f9c0216519eced9d860e5556ad1b617a2d60f3d2bf14c040d66f97d73 2024/01/18 16:33:04 ttl.sh/cosign-ci/50d163ff@sha256:0f4370c876e595a1a250a7a92459d05c599d864d889b52bf4e757c41b9a3e383: digest: sha256:0f4370c876e595a1a250a7a92459d05c599d864d889b52bf4e757c41b9a3e383 size: 858 2024/01/18 16:33:09 pushed blob: sha256:389e76919dd31bb2411fbb10314cc30f157908613be1075a01a4f3245199f026 2024/01/18 16:33:09 pushed blob: sha256:71480e3ad1a769538700b881fdf72cc6dae2bf677996adb552be725eae0a1ad3 2024/01/18 16:33:09 pushed blob: sha256:b552ca26cc53c1f3abe3889e893f89948e779283f39131f9e1987cc9bb916cfd 2024/01/18 16:33:10 ttl.sh/cosign-ci/50d163ff@sha256:8e0034cc92f95fd001f6c68f378f1406c601c94c488f6a8c592eddcdb520aa48: digest: sha256:8e0034cc92f95fd001f6c68f378f1406c601c94c488f6a8c592eddcdb520aa48 size: 837 2024/01/18 16:33:16 pushed blob: sha256:4c7dd8bc1dc91a57e98ce69b554bfa49dc6cd21d45ca2cf10107b9fb93d67d50 2024/01/18 16:33:17 pushed blob: sha256:a5720266a36a5644f0b2ba42a5d9f520e1387f45cbde4248a88e40a616443b89 2024/01/18 16:33:18 ttl.sh/cosign-ci/50d163ff@sha256:0187895b668a1225646bb3454d3373ee8f35bb2122a1d0fda61add9e1a5a5e8b: digest: sha256:0187895b668a1225646bb3454d3373ee8f35bb2122a1d0fda61add9e1a5a5e8b size: 859 2024/01/18 16:33:22 pushed blob: sha256:2f0b375028a5a37f40edaa6c84e8749d1e2e1f28c5c2df6ef7ffe095508d97b5 2024/01/18 16:33:22 pushed blob: sha256:3d2660304ce8f47342b14eca3754b7c721294f5efac2f21ceca72223c36d8193 2024/01/18 16:33:23 pushed blob: sha256:d757cbfa15329645dfeda160467602c2051a063b2032fd43a24cb73c0ee24a3b 2024/01/18 16:33:23 ttl.sh/cosign-ci/50d163ff@sha256:22d74528ed073caa52460d9b6baf390936650dd51890bc6f902e7e92f53b7a74: digest: sha256:22d74528ed073caa52460d9b6baf390936650dd51890bc6f902e7e92f53b7a74 size: 837 2024/01/18 16:33:28 pushed blob: sha256:6da01a2adf08229162b1895c721a56c11d85be743d4f8d054665580415306794 2024/01/18 16:33:33 pushed blob: sha256:8fbec2883728992e7fea45a378e8bc4da6dd4ed593f17cef53a9483e31aafeb7 2024/01/18 16:33:34 ttl.sh/cosign-ci/50d163ff@sha256:b0c2272ad8db09cf9c9fbb8a7fb00fbac694a92441af4d7287eaa4b2f8a23f6d: digest: sha256:b0c2272ad8db09cf9c9fbb8a7fb00fbac694a92441af4d7287eaa4b2f8a23f6d size: 858 2024/01/18 16:33:40 pushed blob: sha256:f53eb0fd99b1b62865d07e3d0b9642d74f970a35899349671abdb8e64ffef377 2024/01/18 16:33:40 pushed blob: sha256:5692ee2cb7ee507529a9b00259f962788a9ca700b30d29869c8beeb6cc2e4ffc 2024/01/18 16:33:41 pushed blob: sha256:00bb1133459aab5070abc3bfe6afeecedebbdd9e2042766c2bdc1ebbe8c60d1d 2024/01/18 16:33:41 ttl.sh/cosign-ci/50d163ff@sha256:dbd30f6329ea3e6c32ef552a114674d634093d4e8308cb19d8ee6bfcf8c06093: digest: sha256:dbd30f6329ea3e6c32ef552a114674d634093d4e8308cb19d8ee6bfcf8c06093 size: 837 2024/01/18 16:33:43 ttl.sh/cosign-ci/50d163ff:1h: digest: sha256:ba76950ac9eaa407512c9d859cea48114eeff8a6f12ebaa5d32ce79d4a017dd8 size: 9517 + IMAGE_URI_DIGEST=ttl.sh/cosign-ci/50d163ff@sha256:ba76950ac9eaa407512c9d859cea48114eeff8a6f12ebaa5d32ce79d4a017dd8 + ./cosign initialize Root status: { "local": "/home/mukul/.sigstore/root", "remote": "https://tuf-repo-cdn.sigstore.dev", "metadata": { "root.json": { "version": 8, "len": 5406, "expiration": "26 Mar 24 04:38 UTC", "error": "" }, "snapshot.json": { "version": 122, "len": 2302, "expiration": "06 Feb 24 16:06 UTC", "error": "" }, "targets.json": { "version": 8, "len": 5254, "expiration": "26 Mar 24 05:51 UTC", "error": "" }, "timestamp.json": { "version": 150, "len": 723, "expiration": "23 Jan 24 16:06 UTC", "error": "" } }, "targets": [ "fulcio_v1.crt.pem", "rekor.pub", "trusted_root.json", "artifact.pub", "ctfe.pub", "ctfe_2022.pub", "fulcio.crt.pem", "fulcio_intermediate_v1.crt.pem" ] } + ./cosign generate ttl.sh/cosign-ci/50d163ff@sha256:ba76950ac9eaa407512c9d859cea48114eeff8a6f12ebaa5d32ce79d4a017dd8 + openssl dgst -sha256 -sign ./private_key -out payload.sig payload.json + cat payload.sig + base64 + openssl dgst -sha256 -sign ./secondprivate_key -out secondpayload.sig payload.json + cat secondpayload.sig + base64 ++ cat payloadbase64.sig ++ base64 + SIGNATURE='b25rY2pSbkpRVUZFcWFuRnlpK0dwWEJqWmQ1WnNCaVMxUVV1NmNDck1oNngwb2xwTitBN0lUSTVu YTlMRVFJSWNBSGpiTVJVV1p1NQoyaFdTb25zNzhoWTI1QmVoRVFwaGtZTElyRlloZnlDZnRsbmFG YkNvTjQ4RHRWSGl0WHplM0cveWVqbzJVamN2SHk5Q3h5VmFQWXBrCnd4UVdDckxrTjNxTUFsYnJZ bzY5R0J0ZXN6eW0zY0grTVRGTWVsR3E2OTVibXYxbXR0Ni91SGR0VzVBT3ZLRStsOW5VVjlZbit3 cGMKUU1BVGROb0U1RlJjRjcvRmNqbk83US9meFR1U2k2OW9FUVV1Njd3Zm1hS0ZQVW9kUTFGRklr L2E5cEFxenpTVkNGcEhjR1ZyNlhNcgpPYkZZeHdWSWc2bUozOFdMWnc5d3I0WEd5MjdzUEpqWG01 Rk5mUT09Cg==' + echo 'Signature: b25rY2pSbkpRVUZFcWFuRnlpK0dwWEJqWmQ1WnNCaVMxUVV1NmNDck1oNngwb2xwTitBN0lUSTVu YTlMRVFJSWNBSGpiTVJVV1p1NQoyaFdTb25zNzhoWTI1QmVoRVFwaGtZTElyRlloZnlDZnRsbmFG YkNvTjQ4RHRWSGl0WHplM0cveWVqbzJVamN2SHk5Q3h5VmFQWXBrCnd4UVdDckxrTjNxTUFsYnJZ bzY5R0J0ZXN6eW0zY0grTVRGTWVsR3E2OTVibXYxbXR0Ni91SGR0VzVBT3ZLRStsOW5VVjlZbit3 cGMKUU1BVGROb0U1RlJjRjcvRmNqbk83US9meFR1U2k2OW9FUVV1Njd3Zm1hS0ZQVW9kUTFGRklr L2E5cEFxenpTVkNGcEhjR1ZyNlhNcgpPYkZZeHdWSWc2bUozOFdMWnc5d3I0WEd5MjdzUEpqWG01 Rk5mUT09Cg==' Signature: b25rY2pSbkpRVUZFcWFuRnlpK0dwWEJqWmQ1WnNCaVMxUVV1NmNDck1oNngwb2xwTitBN0lUSTVu YTlMRVFJSWNBSGpiTVJVV1p1NQoyaFdTb25zNzhoWTI1QmVoRVFwaGtZTElyRlloZnlDZnRsbmFG YkNvTjQ4RHRWSGl0WHplM0cveWVqbzJVamN2SHk5Q3h5VmFQWXBrCnd4UVdDckxrTjNxTUFsYnJZ bzY5R0J0ZXN6eW0zY0grTVRGTWVsR3E2OTVibXYxbXR0Ni91SGR0VzVBT3ZLRStsOW5VVjlZbit3 cGMKUU1BVGROb0U1RlJjRjcvRmNqbk83US9meFR1U2k2OW9FUVV1Njd3Zm1hS0ZQVW9kUTFGRklr L2E5cEFxenpTVkNGcEhjR1ZyNlhNcgpPYkZZeHdWSWc2bUozOFdMWnc5d3I0WEd5MjdzUEpqWG01 Rk5mUT09Cg== ++ cat secondpayloadbase64.sig ++ base64 + SIGNATURE2='UUtxSmt2NmswUTRaOGZ5L0JXVjFVaVQxMXpkcThBazYySE9abHI2bzVXbm1JVG1taFFSdFREaC9R L0lxdlcrN1A2Q2FHOWdQeE1aZApXbkZXWmFSRHBCM3IvbWpIdE9uUHdvL00wTS9iV2lSNmxQYytZ Wm5ESVlDeDhxSVNQUkxWZGRmc2lyMEVYMU9pVGZJcTN6bkM0M0RTCk1Uc3UzTTd2L0pCemMvNm5p NG5FakFmaE1tdnBQaE5KVjFxYm55TU8yVE1LV3pCRnFCVTd6aEF0em03MzdWWHdhR1IvYTMzNm9O WkgKOXc4TXJBMk9uSFExcnFvVGVaM05nVGRTYlFXUFphdFJoM2s0bGRkU1VKeEUzMnM5em1qNEdL SHV3MXJxdXVXS2tUQjRZSkRmWkRmawoyUHJ6a3hvdnVSWWtXZGcwSFNvWUhFL0lhN0FXU1pHSHNh ckd2QT09Cg==' + echo 'Second Signature: UUtxSmt2NmswUTRaOGZ5L0JXVjFVaVQxMXpkcThBazYySE9abHI2bzVXbm1JVG1taFFSdFREaC9R L0lxdlcrN1A2Q2FHOWdQeE1aZApXbkZXWmFSRHBCM3IvbWpIdE9uUHdvL00wTS9iV2lSNmxQYytZ Wm5ESVlDeDhxSVNQUkxWZGRmc2lyMEVYMU9pVGZJcTN6bkM0M0RTCk1Uc3UzTTd2L0pCemMvNm5p NG5FakFmaE1tdnBQaE5KVjFxYm55TU8yVE1LV3pCRnFCVTd6aEF0em03MzdWWHdhR1IvYTMzNm9O WkgKOXc4TXJBMk9uSFExcnFvVGVaM05nVGRTYlFXUFphdFJoM2s0bGRkU1VKeEUzMnM5em1qNEdL SHV3MXJxdXVXS2tUQjRZSkRmWkRmawoyUHJ6a3hvdnVSWWtXZGcwSFNvWUhFL0lhN0FXU1pHSHNh ckd2QT09Cg==' Second Signature: UUtxSmt2NmswUTRaOGZ5L0JXVjFVaVQxMXpkcThBazYySE9abHI2bzVXbm1JVG1taFFSdFREaC9R L0lxdlcrN1A2Q2FHOWdQeE1aZApXbkZXWmFSRHBCM3IvbWpIdE9uUHdvL00wTS9iV2lSNmxQYytZ Wm5ESVlDeDhxSVNQUkxWZGRmc2lyMEVYMU9pVGZJcTN6bkM0M0RTCk1Uc3UzTTd2L0pCemMvNm5p NG5FakFmaE1tdnBQaE5KVjFxYm55TU8yVE1LV3pCRnFCVTd6aEF0em03MzdWWHdhR1IvYTMzNm9O WkgKOXc4TXJBMk9uSFExcnFvVGVaM05nVGRTYlFXUFphdFJoM2s0bGRkU1VKeEUzMnM5em1qNEdL SHV3MXJxdXVXS2tUQjRZSkRmWkRmawoyUHJ6a3hvdnVSWWtXZGcwSFNvWUhFL0lhN0FXU1pHSHNh ckd2QT09Cg== ++ cat payload.json + PAYLOAD='{"critical":{"identity":{"docker-reference":"ttl.sh/cosign-ci/50d163ff"},"image":{"docker-manifest-digest":"sha256:ba76950ac9eaa407512c9d859cea48114eeff8a6f12ebaa5d32ce79d4a017dd8"},"type":"cosign container image signature"},"optional":null}' + echo 'Payload: {"critical":{"identity":{"docker-reference":"ttl.sh/cosign-ci/50d163ff"},"image":{"docker-manifest-digest":"sha256:ba76950ac9eaa407512c9d859cea48114eeff8a6f12ebaa5d32ce79d4a017dd8"},"type":"cosign container image signature"},"optional":null}' Payload: {"critical":{"identity":{"docker-reference":"ttl.sh/cosign-ci/50d163ff"},"image":{"docker-manifest-digest":"sha256:ba76950ac9eaa407512c9d859cea48114eeff8a6f12ebaa5d32ce79d4a017dd8"},"type":"cosign container image signature"},"optional":null} + ./cosign attach signature --signature ./payloadbase64.sig --payload ./payload.json --cert ./leafcert.pem --cert-chain ./certchain.pem ttl.sh/cosign-ci/50d163ff@sha256:ba76950ac9eaa407512c9d859cea48114eeff8a6f12ebaa5d32ce79d4a017dd8 + ./cosign attach signature --signature ./secondpayloadbase64.sig --payload ./payload.json --cert ./secondleafcert.pem --cert-chain ./secondcertchain.pem ttl.sh/cosign-ci/50d163ff@sha256:ba76950ac9eaa407512c9d859cea48114eeff8a6f12ebaa5d32ce79d4a017dd8 + grep -q application/vnd.oci.image.config.v1+json ++ ./cosign triangulate ttl.sh/cosign-ci/50d163ff@sha256:ba76950ac9eaa407512c9d859cea48114eeff8a6f12ebaa5d32ce79d4a017dd8 + crane manifest ttl.sh/cosign-ci/50d163ff:sha256-ba76950ac9eaa407512c9d859cea48114eeff8a6f12ebaa5d32ce79d4a017dd8.sig + grep -q dev.sigstore.cosign/certificate ++ ./cosign triangulate ttl.sh/cosign-ci/50d163ff@sha256:ba76950ac9eaa407512c9d859cea48114eeff8a6f12ebaa5d32ce79d4a017dd8 + crane manifest ttl.sh/cosign-ci/50d163ff:sha256-ba76950ac9eaa407512c9d859cea48114eeff8a6f12ebaa5d32ce79d4a017dd8.sig + grep -q dev.sigstore.cosign/chain ++ ./cosign triangulate ttl.sh/cosign-ci/50d163ff@sha256:ba76950ac9eaa407512c9d859cea48114eeff8a6f12ebaa5d32ce79d4a017dd8 + crane manifest ttl.sh/cosign-ci/50d163ff:sha256-ba76950ac9eaa407512c9d859cea48114eeff8a6f12ebaa5d32ce79d4a017dd8.sig + ./cosign verify ttl.sh/cosign-ci/50d163ff@sha256:ba76950ac9eaa407512c9d859cea48114eeff8a6f12ebaa5d32ce79d4a017dd8 --insecure-ignore-sct --insecure-ignore-tlog --certificate-identity-regexp '.*' --certificate-oidc-issuer-regexp '.*' --cert-chain=./rootcert.pem WARNING: Skipping tlog verification is an insecure practice that lacks of transparency and auditability verification for the signature. Verification for ttl.sh/cosign-ci/50d163ff@sha256:ba76950ac9eaa407512c9d859cea48114eeff8a6f12ebaa5d32ce79d4a017dd8 -- The following checks were performed on each of these signatures: - The cosign claims were validated - The code-signing certificate was verified using trusted certificate authority certificates [{"critical":{"identity":{"docker-reference":"ttl.sh/cosign-ci/50d163ff"},"image":{"docker-manifest-digest":"sha256:ba76950ac9eaa407512c9d859cea48114eeff8a6f12ebaa5d32ce79d4a017dd8"},"type":"cosign container image signature"},"optional":{"Subject":"foo@example.com"}}] + ./cosign verify ttl.sh/cosign-ci/50d163ff@sha256:ba76950ac9eaa407512c9d859cea48114eeff8a6f12ebaa5d32ce79d4a017dd8 --insecure-ignore-sct --insecure-ignore-tlog --certificate-identity-regexp '.*' --certificate-oidc-issuer-regexp '.*' --cert-chain=./secondrootcert.pem WARNING: Skipping tlog verification is an insecure practice that lacks of transparency and auditability verification for the signature. Verification for ttl.sh/cosign-ci/50d163ff@sha256:ba76950ac9eaa407512c9d859cea48114eeff8a6f12ebaa5d32ce79d4a017dd8 -- The following checks were performed on each of these signatures: - The cosign claims were validated - The code-signing certificate was verified using trusted certificate authority certificates [{"critical":{"identity":{"docker-reference":"ttl.sh/cosign-ci/50d163ff"},"image":{"docker-manifest-digest":"sha256:ba76950ac9eaa407512c9d859cea48114eeff8a6f12ebaa5d32ce79d4a017dd8"},"type":"cosign container image signature"},"optional":{"Subject":"foo@exampleclient.com"}}] + ./cosign clean ttl.sh/cosign-ci/50d163ff@sha256:ba76950ac9eaa407512c9d859cea48114eeff8a6f12ebaa5d32ce79d4a017dd8 --force=true Removed ttl.sh/cosign-ci/50d163ff:sha256-ba76950ac9eaa407512c9d859cea48114eeff8a6f12ebaa5d32ce79d4a017dd8.sig from ttl.sh/cosign-ci/50d163ff@sha256:ba76950ac9eaa407512c9d859cea48114eeff8a6f12ebaa5d32ce79d4a017dd8 + crane delete ttl.sh/cosign-ci/50d163ff@sha256:ba76950ac9eaa407512c9d859cea48114eeff8a6f12ebaa5d32ce79d4a017dd8 + echo SUCCESS SUCCESS