Class GovernanceSignatureInput
Builds the exact bytes a signing provider signs and a verification provider verifies for a governance artifact.
public static class GovernanceSignatureInput
- Inheritance
-
GovernanceSignatureInput
- Inherited Members
Remarks
Before 6.0, providers signed only the UTF-8 text of the canonical payload hash. Every other value recorded in SigningMetadata, including the signing policy version and policy hash, was an unauthenticated label: a holder of a validly signed artifact could relabel it and verification still succeeded.
The version 1 signature input is a canonical JSON document that binds the format identifier, the canonical artifact
descriptors, the hash algorithm, the hash value, and the signing policy context recorded under
PolicyVersionMetadataKey and PolicyHashMetadataKey. An absent policy value is bound as
JSON null, so adding, removing, or changing a policy label after signing invalidates the signature.
Key identifier, key version, provider, and signing timestamp are not part of the input, because managed-key providers commonly resolve the key version and timestamp during signing. They are authenticated only to the extent that the verification service resolves its verification key from KeyId and KeyVersion and rejects a Provider it does not own.
Fields
FormatV1
Identifies the version 1 signature input format.
public const string FormatV1 = "asibackbone.signature-input.v1"
Field Value
PolicyHashMetadataKey
The signing metadata key whose value is bound into the version 1 signature input as the signing policy hash.
public const string PolicyHashMetadataKey = "policy_hash"
Field Value
PolicyVersionMetadataKey
The signing metadata key whose value is bound into the version 1 signature input as the signing policy version.
public const string PolicyVersionMetadataKey = "policy_version"
Field Value
Methods
CreateLegacy(string)
Creates the pre-6.0 signature input: the UTF-8 text of the signing hash alone.
public static ReadOnlyMemory<byte> CreateLegacy(string signingHash)
Parameters
signingHashstringThe canonical payload hash value.
Returns
- ReadOnlyMemory<byte>
The UTF-8 bytes of the trimmed signing hash.
Remarks
This input authenticates the canonical payload hash only. Core uses it for artifacts signed before 6.0 when a verification context explicitly opts in through WithLegacySignatureInputAllowed(), and as the fallback for provider requests constructed without an explicit signature input.
CreateV1(CanonicalPayloadHash, IReadOnlyDictionary<string, string>?)
Creates the version 1 signature input for a canonical payload hash and the signing policy context in the supplied signing metadata.
public static ReadOnlyMemory<byte> CreateV1(CanonicalPayloadHash canonicalHash, IReadOnlyDictionary<string, string>? signingMetadata = null)
Parameters
canonicalHashCanonicalPayloadHashThe canonical payload hash being signed or verified.
signingMetadataIReadOnlyDictionary<string, string>Signing metadata supplying the PolicyVersionMetadataKey and PolicyHashMetadataKey values. Missing, empty, or whitespace-only values are bound as JSON
null; other values are trimmed.
Returns
- ReadOnlyMemory<byte>
The UTF-8 canonical JSON bytes to sign or verify.