My new blog post on Red Hat Developers is about how to verify the digital signature from Red Hat container images and how to preserve that level of trust when you mirror those images into your private registry server. It nicely complements the image signing and verification content from DO425:
https://developers.redhat.com/blog/2019/10/29/verifying-signatures-of-red-hat-container-images/
Great write-up :)
Red Hat
Learning Community
A collaborative learning environment, enabling open source skill development.