summaryrefslogtreecommitdiff
path: root/PlantUML-ModelingTrust/GnuPG-WoT-Download/README.adoc
blob: fe1010ab07da4d6f7bef75c5a1c0521b786d77c1 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
= PLantUML Diagrams for GnuPG Key Signing

I am trying to model implicit and explicit trust in Zero Trust Architecture diagrams for Threat Modeling. 

So I need to bring together the Blue Team/White Hat perspective and the Red Team/Black Hat stuff. 

== DFD: Keysigning Simple

image::100-GnuPG-Keysigning-DFD.png[]

== SEQ: Keysigning with ID check and WoT

image::100-GnuPG-Keysigning-SEQ-KSP-WoT.png[]



== NetBSD RelEng Attack STRIDE

The ISO Image is built, signed and uploaded to the WWW server, as well as the Signature file and checksums. 

Evil Black Hat hacks the webserver, and swaps the ISO image for a manipulated one with a valid Signature. 

The manipulated Signature verifies the fake-integrity of the manipulated ISO image, but not the authenticity. 

image::300-NetBSD-RelEng-STRIDE.png[]




== Supply-chain Levels for Software Artifacts

A simple threat model for SLSA Level 1 and Leve 4 build and distribution pipelines. 

image::200-ThreatModel-SLSA1-DownloadSig.png[]



image::201-ThreatModel-SLSA4-ReproducibleBuilds.png[]