Table of Contents

Class LocalDevelopmentSigningOptions

Namespace
AsiBackbone.Signing.LocalDevelopment
Assembly
AsiBackbone.Signing.LocalDevelopment.dll

Configures the local-development signing provider.

public sealed class LocalDevelopmentSigningOptions
Inheritance
LocalDevelopmentSigningOptions
Inherited Members

Remarks

This provider is intended for local development, samples, and tests. It is not a production managed-key provider and does not create tamper-evidence by itself.

Fields

DefaultKeyId

Gets the default local-development key identifier.

public const string DefaultKeyId = "local-dev-key"

Field Value

string

DefaultKeySizeBits

Gets the default RSA key size for generated local-development keys.

public const int DefaultKeySizeBits = 2048

Field Value

int

DefaultKeyVersion

Gets the default local-development key version.

public const string DefaultKeyVersion = "dev"

Field Value

string

DefaultProviderName

Gets the default provider descriptor returned in signing metadata.

public const string DefaultProviderName = "local-development"

Field Value

string

DefaultSignatureAlgorithm

Gets the default provider-neutral signature algorithm descriptor.

public const string DefaultSignatureAlgorithm = "RSASSA-PSS-SHA256-LOCAL-DEV"

Field Value

string

MinimumKeySizeBits

Gets the minimum supported RSA key size for generated local-development keys.

public const int MinimumKeySizeBits = 2048

Field Value

int

Properties

AllowInProduction

Gets or sets a value indicating whether this provider may be registered while the host reports a production environment.

public bool AllowInProduction { get; set; }

Property Value

bool

Remarks

The signing key is generated per process and never persisted, so signatures produced by this provider stop verifying after a restart and carry no key custody story. Registration therefore fails in production unless a host states this intent explicitly.

EnvironmentName

Gets or sets the environment name used by the production guard, overriding the ambient environment variables.

public string? EnvironmentName { get; set; }

Property Value

string

Remarks

When null, the guard reads DOTNET_ENVIRONMENT and then ASPNETCORE_ENVIRONMENT. This package does not depend on the hosting abstractions, so a host that determines its environment another way supplies the name here.

KeyId

Gets or sets the local-development key identifier returned in signing metadata.

public string KeyId { get; set; }

Property Value

string

KeySizeBits

Gets or sets the generated RSA key size in bits.

public int KeySizeBits { get; set; }

Property Value

int

Remarks

Values below MinimumKeySizeBits are invalid. Omitted configuration uses DefaultKeySizeBits.

KeyVersion

Gets or sets the local-development key version returned in signing metadata.

public string KeyVersion { get; set; }

Property Value

string

ProviderName

Gets or sets the provider descriptor returned in signing metadata.

public string ProviderName { get; set; }

Property Value

string

ReturnUnsignedOnFailure

Gets or sets a value indicating whether signing failures should return unsigned metadata with explicit failure details instead of throwing during normal signing flow.

public bool ReturnUnsignedOnFailure { get; set; }

Property Value

bool

SignatureAlgorithm

Gets or sets the signature algorithm descriptor returned in signing metadata.

public string SignatureAlgorithm { get; set; }

Property Value

string

Methods

Create(string?, string?, string?, string?, int, bool, bool, string?)

Creates options for the local-development signing provider.

public static LocalDevelopmentSigningOptions Create(string? providerName = null, string? keyId = null, string? keyVersion = null, string? signatureAlgorithm = null, int keySizeBits = 2048, bool returnUnsignedOnFailure = true, bool allowInProduction = false, string? environmentName = null)

Parameters

providerName string
keyId string
keyVersion string
signatureAlgorithm string
keySizeBits int
returnUnsignedOnFailure bool
allowInProduction bool
environmentName string

Returns

LocalDevelopmentSigningOptions

Validate()

Validates the configured local-development signing options.

public void Validate()

Exceptions

InvalidOperationException

Thrown when KeySizeBits is below MinimumKeySizeBits.