ARTIFACTORY: Managing and Understanding Signing Keys in Artifactory

ARTIFACTORY: Managing and Understanding Signing Keys in Artifactory

AuthorFullName__c
Scott Mosher
articleNumber
000005366
ft:sourceType
Salesforce
FirstPublishedDate
2022-08-10T07:37:26Z
lastModifiedDate
2022-08-10
VersionNumber
3

For this article, we want to understand the use and setup for signing and verifying Artifactory generated artifacts. Artifactory will not and cannot sign for packages it does not create.  Artifactory generates its own metadata files for all packages so that is what we can sign for RPM and Debian repositories.