Table of Contents

Class GovernanceSignatureInput

Namespace
AsiBackbone.Core.Signing
Assembly
AsiBackbone.Core.dll

Builds the exact bytes a signing provider signs and a verification provider verifies for a governance artifact.

public static class GovernanceSignatureInput
Inheritance
GovernanceSignatureInput
Inherited Members

Remarks

Before 6.0, providers signed only the UTF-8 text of the canonical payload hash. Every other value recorded in SigningMetadata, including the signing policy version and policy hash, was an unauthenticated label: a holder of a validly signed artifact could relabel it and verification still succeeded.

The version 1 signature input is a canonical JSON document that binds the format identifier, the canonical artifact descriptors, the hash algorithm, the hash value, and the signing policy context recorded under PolicyVersionMetadataKey and PolicyHashMetadataKey. An absent policy value is bound as JSON null, so adding, removing, or changing a policy label after signing invalidates the signature.

Key identifier, key version, provider, and signing timestamp are not part of the input, because managed-key providers commonly resolve the key version and timestamp during signing. They are authenticated only to the extent that the verification service resolves its verification key from KeyId and KeyVersion and rejects a Provider it does not own.

Fields

FormatV1

Identifies the version 1 signature input format.

public const string FormatV1 = "asibackbone.signature-input.v1"

Field Value

string

PolicyHashMetadataKey

The signing metadata key whose value is bound into the version 1 signature input as the signing policy hash.

public const string PolicyHashMetadataKey = "policy_hash"

Field Value

string

PolicyVersionMetadataKey

The signing metadata key whose value is bound into the version 1 signature input as the signing policy version.

public const string PolicyVersionMetadataKey = "policy_version"

Field Value

string

Methods

CreateLegacy(string)

Creates the pre-6.0 signature input: the UTF-8 text of the signing hash alone.

public static ReadOnlyMemory<byte> CreateLegacy(string signingHash)

Parameters

signingHash string

The canonical payload hash value.

Returns

ReadOnlyMemory<byte>

The UTF-8 bytes of the trimmed signing hash.

Remarks

This input authenticates the canonical payload hash only. Core uses it for artifacts signed before 6.0 when a verification context explicitly opts in through WithLegacySignatureInputAllowed(), and as the fallback for provider requests constructed without an explicit signature input.

CreateV1(CanonicalPayloadHash, IReadOnlyDictionary<string, string>?)

Creates the version 1 signature input for a canonical payload hash and the signing policy context in the supplied signing metadata.

public static ReadOnlyMemory<byte> CreateV1(CanonicalPayloadHash canonicalHash, IReadOnlyDictionary<string, string>? signingMetadata = null)

Parameters

canonicalHash CanonicalPayloadHash

The canonical payload hash being signed or verified.

signingMetadata IReadOnlyDictionary<string, string>

Signing metadata supplying the PolicyVersionMetadataKey and PolicyHashMetadataKey values. Missing, empty, or whitespace-only values are bound as JSON null; other values are trimmed.

Returns

ReadOnlyMemory<byte>

The UTF-8 canonical JSON bytes to sign or verify.