public anchors · sha-256
Verify
These are the public halves of the cairn key set. I publish them here so a cairn-signed image, UKI, or kernel module can be checked against a fingerprint fetched out-of-band, without trusting the registry that served the artifact. The check is always the same: download a file, run its verify command, and compare against the fingerprint printed below.
The trust chain
Secure Boot: the Platform Key owns the firmware and authorizes the KEK; the KEK authorizes the signature database (db). db holds cairn's UKI signing certificate alongside the Microsoft and Windows vendor CAs, kept so 2011-chained option ROMs still load. The cairn cert is the one that signs what actually runs: systemd-boot, every unified kernel image, and the ZFS/NVIDIA kernel modules baked into the images.
Measured boot: each UKI carries a TPM PCR11 policy
signed by the PCR11 policy key, so TPM2
unsealing extends only to kernels the estate signed. Images: where a repo turns on signing
(sign_on_promote), the promoted digest is signed by the cosign key. That is own-key signing with no
transparency log, so these fingerprints are the only anchor there is.
The same anchors live in the public repo under keys/,
and the machine-readable list is fingerprints.txt.
Those are two independent out-of-band paths to the same values, and the
table below is parsed from that same file at build time: the build fails
if the published copies drift from the canonical anchors, or if the file
and this page disagree on even one entry. No private half appears in this
repo: PK and KEK stay in offline escrow, and the three signing keys exist
only as masked, protected CI variables
(the trust chain).
Fingerprints
PK · Platform Key
CN=cairn Platform Key, O=cairn.dunn.dev
sha-256 fingerprint
B2:23:AE:9A:5A:7F:C8:5A36:ED:17:85:9F:ED:BD:E82F:45:E5:9F:80:37:DB:C332:91:68:9B:82:4B:7D:87
Firmware ownership root. Enrolled as the UEFI Platform Key; the only key that authorizes changes to the KEK.
openssl x509 -in PK.crt -noout -subject -fingerprint -sha256
KEK · Key Exchange Key
CN=cairn Key Exchange Key, O=cairn.dunn.dev
sha-256 fingerprint
D4:E9:03:DA:CE:06:F3:D042:01:CA:B2:2C:74:18:FFC9:8A:56:EE:03:CC:A6:92F4:83:15:49:6C:94:20:9B
Authorizes updates to the Secure Boot signature databases (db/dbx). Signed into the hierarchy under the PK.
openssl x509 -in KEK.crt -noout -subject -fingerprint -sha256
UKI · UKI signing certificate
CN=cairn UKI signing, O=cairn.dunn.dev
sha-256 fingerprint
A4:19:A8:25:C8:78:52:43C2:1F:23:74:C1:8B:49:8E4E:51:59:B4:83:2E:5B:ED3C:EF:46:88:A4:1E:F4:C6
db member. Signs systemd-boot, every unified kernel image (UKI) the estate promotes, and the out-of-tree ZFS/NVIDIA kernel modules baked into the images.
openssl x509 -in UKI.crt -noout -subject -fingerprint -sha256
pcr11 · PCR11 policy public key
RSA public key (no certificate)
sha-256 fingerprint
0f0dbb4eecba169e5c036c4b45707a3371bece1f7f1795fdec6e9e1327aabe4f
Verifies the signed TPM PCR11 policy each UKI carries (systemd-measure); TPM2 unsealing trusts UKIs it vouches for.
openssl pkey -pubin -in pcr11.pub.pem -outform DER | sha256sum
cosign · Image signing public key
ECDSA public key (no certificate)
sha-256 fingerprint
03bd99155ffaa044a97f2c6b2cff56aae83195df65f83a58abab5eda404d7ef7
Verifies the cosign signature on estate-signed image digests (opt-in sign_on_promote at promotion).
sha256sum cosign.pub
Verify a promoted image
To check the cosign signature on a signed digest, use the published key. The estate signs with its own key rather than a keyless transparency-log identity, so the tlog check is turned off. Trust comes from this fingerprint instead, fetched out-of-band:
cosign verify --key cosign.pub --insecure-ignore-tlog=true <image>@<digest>
On a running cairn host, confirm a kernel module was signed by the estate's UKI key:
modinfo -F signer zfs # → cairn UKI signing
Everything at once
Every anchor is published verbatim at a stable URL under /keys/:
PK.crt ·
KEK.crt ·
UKI.crt ·
pcr11.pub.pem ·
cosign.pub
· fingerprints.txt
· README.md