Skip to content

How-to Guides

Task-oriented guides for signing and verifying release artefacts with sigillum. Each guide assumes you already know the basics (see Getting Started) and walks through one concrete task.

  • Sign a release artefact — produce a detached OpenPGP signature with the AWS KMS or local PEM backend, and verify it.
  • Generate or mint a signing key — generate a fresh keypair locally, or mint an OpenPGP public key from an existing signer (e.g. a KMS key).
  • Publish a WKD tree — generate and deploy a Web Key Directory so verifiers can cross-check your public keys against an externally-served copy.