Skip to content

Enable trust pinning with docker content trust  #84

Description

@cyc115

Description
The current version of notary currently support two types of trust pinnings: 1) certificate pinning that pins to a specific certificate and 2) CA pinning that uses a provided certificate of a trusted CA to validate the leaf certificate in the metadata.

Having the ability to pin to a trusted certificate/CA is extremely important as the current TUFUs model does not prevent MIMA for those who is pulling from the repository for the very first time.

At the moment, this feature seems to be disabled as an empty trust pin config is being passed into client.NewNotaryRepository().

Activity

  1. changed the title [-]Trust pinning cannot be enabled by docker content trust [/-] [+]Enable trust pinning with docker content trust [/+] on May 15, 2017
  2. thaJeztah commented on Oct 30, 2017

    @thaJeztah
    Member
  3. endophage commented on Oct 30, 2017

    @endophage

    It's in our TODO list for the next round of docker trust additions. Early thoughts on the CLI syntax can be found in the "Configuring Trust in Docker" section of this doc: https://docs.google.com/document/d/1JOBAlCDuf5JnpVLW54voGuAdsnMmSR2LIbs8fjBDSaM/

    I talked to @cyc115 about contributing this a while ago. Are you planning to take this on or is this issue a feature request? If you're planning to implement it, let's bikeshed in this issue a little on the syntax, because I've been thinking maybe it could be shortened from docker trust config pin ... in that doc, to just docker trust pin ...

    Also, we should decide in pin is the term we want to use. Security people will understand it, but if there's a more intuitive term we can use we're not married to pin. Remember that one of the goals of the docker trust command is to be more intuitive than notary and to hide the TUF concepts behind something much more friendly to the typical user.

  4. dbilling commented on Aug 30, 2018

    @dbilling

    This feature is super important...Any updates on progress? Is there a potential for a workaround? That is, if I have a notary client and configure notary trust pinning commands while the notary trust_dir is set to ~/.docker/trust, will docker's imbedded notary component pick it up and honor the config?

  5. maltfield commented on Sep 29, 2020

    @maltfield

    See also this issue, which would require explicit user approval before TOFU

  6. added 2 commits that reference this issue on Nov 19, 2025
  7. thaJeztah commented on May 14, 2026

    @thaJeztah
    Member
  8. maltfield commented on May 14, 2026

    @maltfield

    So, uhh, you guys just decided to give up on any chance of providing security in docker?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions