Table of Contents

Class VerificationPolicyContext

Namespace
AsiBackbone.Core.Signing
Assembly
AsiBackbone.Core.dll

Provides host expectations used while evaluating signature verification policy.

public sealed class VerificationPolicyContext
Inheritance
VerificationPolicyContext
Inherited Members

Remarks

The context is provider-neutral. It can carry expected key references, policy identifiers, and request metadata without resolving provider-specific keys in Core.

Properties

AllowLegacySignatureInput

Gets a value indicating whether verification may fall back to the pre-6.0 hash-only signature input.

public bool AllowLegacySignatureInput { get; }

Property Value

bool

Remarks

Defaults to false. When enabled, an artifact whose version 1 verification fails as an invalid signature is verified again against CreateLegacy(string). A legacy signature authenticates the canonical payload hash only, so it cannot satisfy ExpectedPolicyVersion or ExpectedPolicyHash; such pins deny with signature.policy-context-not-authenticated.

Default

Gets a context with no additional host expectations.

public static VerificationPolicyContext Default { get; }

Property Value

VerificationPolicyContext

ExpectedKeyId

Gets the expected signing key identifier, when required by host policy.

public string? ExpectedKeyId { get; }

Property Value

string

ExpectedKeyVersion

Gets the expected signing key version, when required by host policy.

public string? ExpectedKeyVersion { get; }

Property Value

string

ExpectedPolicyHash

Gets the expected policy hash, when the signed metadata is expected to carry one.

public string? ExpectedPolicyHash { get; }

Property Value

string

ExpectedPolicyVersion

Gets the expected policy version, when the signed metadata is expected to carry one.

public string? ExpectedPolicyVersion { get; }

Property Value

string

HasMetadata

Gets a value indicating whether additional metadata is present.

public bool HasMetadata { get; }

Property Value

bool

Metadata

Gets additional provider-neutral verification request metadata.

public IReadOnlyDictionary<string, string> Metadata { get; }

Property Value

IReadOnlyDictionary<string, string>

Purpose

Gets the host-defined verification purpose.

public string? Purpose { get; }

Property Value

string

RequiredHashAlgorithm

Gets the required hash algorithm descriptor, when required by host policy.

public string? RequiredHashAlgorithm { get; }

Property Value

string

RequiredProvider

Gets the required signing provider descriptor, when required by host policy.

public string? RequiredProvider { get; }

Property Value

string

Methods

Create(string?, string?, string?, string?, string?, string?, string?, IReadOnlyDictionary<string, string>?)

Creates a provider-neutral verification policy context.

public static VerificationPolicyContext Create(string? purpose = null, string? expectedKeyId = null, string? expectedKeyVersion = null, string? expectedPolicyVersion = null, string? expectedPolicyHash = null, string? requiredProvider = null, string? requiredHashAlgorithm = null, IReadOnlyDictionary<string, string>? metadata = null)

Parameters

purpose string
expectedKeyId string
expectedKeyVersion string
expectedPolicyVersion string
expectedPolicyHash string
requiredProvider string
requiredHashAlgorithm string
metadata IReadOnlyDictionary<string, string>

Returns

VerificationPolicyContext

WithLegacySignatureInputAllowed()

Creates a copy of this context that accepts artifacts signed with the pre-6.0 hash-only signature input.

public VerificationPolicyContext WithLegacySignatureInputAllowed()

Returns

VerificationPolicyContext

A context identical to this one with AllowLegacySignatureInput set.

Remarks

Use this only for reviewing or migrating artifacts signed before 6.0. Signing metadata labels on such artifacts, including the policy version and policy hash, are not covered by the signature.

This opt-in is a supported verification path, not a deprecated one. Governance evidence signed before 6.0 must stay verifiable for its audit-retention period, and removing this method would leave no way to verify it. Producing new hash-only signatures is deprecated separately through CreateLegacy(string) (ASIB902).