How Can Imported Private Images Be Signed Automatically?
Scenarios
To prevent tampering of images published from private environments to Huawei Cloud, IMS provides auto sign for private images. When you create an image from an imported image file, the created image file can be automatically signed. When you use an automatically signed image to create EVS disks (including system and data disks), the created EVS disks automatically verify the image integrity based on the signature and display the verification result.
Constraints
- A signed image cannot be shared with other users.
- Automatic image signing is supported only in the following scenarios:
- Creating a system disk image using an external image file
- Creating a data disk image using an external image file
Auto sign is only available for certain regions. You can see on the console if it is available for a given region.
Procedure
- Creating a signature key
- Log in to the DEW console.
- On the Key Management Service page, click Create Key in the upper right corner.
- On the Create Key page, enter a key name, select a key algorithm, and set Usage to SIGN_VERIFY. Retain the default values for other parameters.
- Use the signature key to automatically sign the image.
- View the image integrity check result.
- After you use the signed image to create an EVS disk, click the target disk on the EVS list page to go to the details page and view the image integrity check result.

- If the image is tampered with, the image integrity check result is Failed.

- After you use the signed image to create an EVS disk, click the target disk on the EVS list page to go to the details page and view the image integrity check result.
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot


