Class VerificationPolicyOptions
Maps signature verification categories to host-facing verification policy actions.
public sealed class VerificationPolicyOptions
- Inheritance
-
VerificationPolicyOptions
- Inherited Members
Properties
Actions
Gets the configured verification category to host action map.
public IReadOnlyDictionary<SignatureVerificationCategory, VerificationPolicyAction> Actions { get; }
Property Value
Default
Gets the default verification policy action map.
public static VerificationPolicyOptions Default { get; }
Property Value
Remarks
Only Valid allows. Every category that reports an integrity or trust failure denies: an invalid or missing signature, a hash, canonicalization, or algorithm mismatch, a revoked or untrusted key, and an untrusted signing context. Only conditions that a retry or an operator could legitimately resolve use softer actions: ProviderUnavailable defers, and UnknownKeyVersion and Failed escalate.
Methods
Create(IReadOnlyDictionary<SignatureVerificationCategory, VerificationPolicyAction>?, bool)
Creates verification policy options with optional host overrides.
public static VerificationPolicyOptions Create(IReadOnlyDictionary<SignatureVerificationCategory, VerificationPolicyAction>? actionOverrides = null, bool allowUnsafeAllowOverrides = false)
Parameters
actionOverridesIReadOnlyDictionary<SignatureVerificationCategory, VerificationPolicyAction>Category to action overrides applied over the defaults.
allowUnsafeAllowOverridesboolWhen true, permits mapping a failure category to Allow. Such a mapping makes a failed verification indistinguishable from a successful one, so it must be opted into deliberately rather than reached by configuration drift.
Returns
Exceptions
- ArgumentOutOfRangeException
A category or action is undefined, or a failure category was mapped to Allow without the opt-in.
GetAction(SignatureVerificationCategory)
Gets the action configured for the supplied verification category.
public VerificationPolicyAction GetAction(SignatureVerificationCategory category)
Parameters
categorySignatureVerificationCategory