Table of Contents

Enum SignatureVerificationCategory

Namespace
AsiBackbone.Core.Signing
Assembly
AsiBackbone.Core.dll

Describes the provider-neutral category assigned to a signature verification result.

public enum SignatureVerificationCategory

Fields

CanonicalizationMismatch = 7

Canonical payload descriptors did not match the artifact being verified.

Defaults to Deny. Signing metadata that describes a different artifact identifier, artifact type, canonicalization version, or payload schema version than the artifact presented means the signature cannot be treated as evidence for that artifact.

Failed = 9

Verification failed but no more specific category could be inferred safely.

HashMismatch = 2

The verification hash did not match the hash recorded in signing metadata.

InvalidSignature = 1

The signature value was present but did not verify.

MissingSignature = 3

Required signature metadata was missing.

Defaults to Deny. An artifact whose signature was stripped carries no proof, so treating it as awaiting acknowledgment would invite a host to proceed on unproven content. Hosts that deliberately accept unsigned artifacts on a lower-assurance path can map this category to another action through Create(IReadOnlyDictionary<SignatureVerificationCategory, VerificationPolicyAction>?, bool).

ProviderUnavailable = 6

The verification provider was unavailable or could not complete verification.

This category describes a transient operational condition only. A signature produced by a provider the verification policy does not require is a trust decision and is reported as UntrustedSigningContext.

RevokedKey = 5

The signing key was revoked, disabled, or otherwise no longer trusted.

UnknownKeyVersion = 4

The signing key identifier or key version could not be resolved or did not match policy expectations.

Unspecified = 0

No verification category was assigned.

Zero is a rejected sentinel so that a default-constructed value, or a persisted column that yields zero for unrecognized input, cannot mean "valid".

UnsupportedAlgorithm = 8

The hash or signature algorithm is unsupported by the configured verifier or policy.

UntrustedKey = 10

The signature was produced under a key the verification policy does not trust for this purpose.

This is distinct from UnknownKeyVersion, which describes a key the verifier could not resolve. An artifact signed under a resolvable but unpinned key is a trust decision rather than a lookup failure, and defaults to Deny.

UntrustedSigningContext = 12

The signature was produced under a signing context the verification policy does not trust, such as a provider other than the required provider or a policy version or policy hash other than the expected one.

Like UntrustedKey, this is a trust decision rather than an operational failure, so it defaults to Deny instead of Defer or Escalate. A retry or a human approval cannot make an artifact signed under the wrong provider or policy context trustworthy.

Valid = 11

The signature verified against the expected artifact hash and metadata.