Loading…
May 21, 2026 | Minneapolis, Minnesota, USA
Learn More and Register To Attend
Schedule is subject to change.

The Sched app allows you to build your schedule, but it is not a substitute for event registration. To participate in the sessions, you must be registered for OpenSSF Community Day NA 2026. If you have not registered but would like to join us, please visit the event registration page to purchase a ticket.












Thursday May 21, 2026 2:00pm - 2:20pm CDT
Keyless signing in sigstore/cosign avoids the need to manage long-lived private keys by using ephemeral keys, short-lived certificates issued by a Managed CA (sigstore/fulcio), and a Public Transparency Log (sigstore/rekor). While this model fits many use cases, some organizations may prefer to run their own infrastructure with an Internal CA and Private Transparency Logs.

At Coinbase, the Security Platform Engineering team built an Internal CA that issues more than 100M certificates per year. We’ve applied keyless signing principles to our build pipelines, where signers attest their workload identities (e.g., SPIFFE, AWS OIDC), receive short-lived X.509 certificates, and sign artifacts with ephemeral keys that are immediately discarded after use.

This talk explores implementing a BYOPKI approach that maintains keyless signing principles, issuing short-lived X.509 certificates using workload attestation, and leveraging the new bundle format (v0.3+) within sigstore/cosign.
Speakers
avatar for Kenneth Yang

Kenneth Yang

Staff Software Engineer, Coinbase
Kenneth is a Staff Software Engineer at Coinbase and ex-Airbnb Security Engineer focusing on Key Management systems. When he’s not getting paged and pulled into incidents he enjoys spending time with his two dogs and being in the outdoors.
avatar for Adrian Smith

Adrian Smith

Senior Software Engineer, Coinbase
Adrian is a software engineer at Coinbase who helps build and maintain PKI systems at scale
Thursday May 21, 2026 2:00pm - 2:20pm CDT
101E

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link