Table of Contents

Class VerificationPolicyOptions

Namespace
AsiBackbone.Core.Signing
Assembly
AsiBackbone.Core.dll

Maps signature verification categories to host-facing verification policy actions.

public sealed class VerificationPolicyOptions
Inheritance
VerificationPolicyOptions
Inherited Members

Properties

Actions

Gets the configured verification category to host action map.

public IReadOnlyDictionary<SignatureVerificationCategory, VerificationPolicyAction> Actions { get; }

Property Value

IReadOnlyDictionary<SignatureVerificationCategory, VerificationPolicyAction>

Default

Gets the default verification policy action map.

public static VerificationPolicyOptions Default { get; }

Property Value

VerificationPolicyOptions

Remarks

Only Valid allows. Every category that reports an integrity or trust failure denies: an invalid or missing signature, a hash, canonicalization, or algorithm mismatch, a revoked or untrusted key, and an untrusted signing context. Only conditions that a retry or an operator could legitimately resolve use softer actions: ProviderUnavailable defers, and UnknownKeyVersion and Failed escalate.

Methods

Create(IReadOnlyDictionary<SignatureVerificationCategory, VerificationPolicyAction>?, bool)

Creates verification policy options with optional host overrides.

public static VerificationPolicyOptions Create(IReadOnlyDictionary<SignatureVerificationCategory, VerificationPolicyAction>? actionOverrides = null, bool allowUnsafeAllowOverrides = false)

Parameters

actionOverrides IReadOnlyDictionary<SignatureVerificationCategory, VerificationPolicyAction>

Category to action overrides applied over the defaults.

allowUnsafeAllowOverrides bool

When true, permits mapping a failure category to Allow. Such a mapping makes a failed verification indistinguishable from a successful one, so it must be opted into deliberately rather than reached by configuration drift.

Returns

VerificationPolicyOptions

Exceptions

ArgumentOutOfRangeException

A category or action is undefined, or a failure category was mapped to Allow without the opt-in.

GetAction(SignatureVerificationCategory)

Gets the action configured for the supplied verification category.

public VerificationPolicyAction GetAction(SignatureVerificationCategory category)

Parameters

category SignatureVerificationCategory

Returns

VerificationPolicyAction