Verify Docker Compose file for online installs


With each Puppet Remediate release, a digital signature is created using the private key portion of an asymmetric key. You can manually validate the signature using the public key portion of the same asymmetric key.

  1. Download the signature file and the public key to the same directory as your docker-compose.yml and license file.
    Note: For instructions on downloading the docker-compose.yml and license files, see the instructions on how to Install Remediate on online nodes.
  2. Run the following command:
    openssl dgst -sha256 -verify -signature signature docker-compose.yml

    If the signature is valid, you get the following response:

    Verified Ok
How helpful was this page?

If you leave us your email, we may contact you regarding your feedback. For more information on how Puppet uses your personal information, see our privacy policy.

Puppet sites use proprietary and third-party cookies. By using our sites, you agree to our cookie policy.