Image with multiple cosign signatures fail verification in RHACS
Issue
- When an image is signed with 2 different keys, an ACS policy what checks validity of the signature fails with the error
invalid signature when validating ASN.1 encoded signature. When checked with cosign directly, the image signature is verified.
Environment
- Red Hat Advance Cluster Security for Kubernetes (RHACS)
- 4.x
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.