Table of Contents

Interface IManagedKeySigningClient

Namespace
AsiBackbone.Signing.ManagedKey
Assembly
AsiBackbone.Signing.ManagedKey.dll

Defines the host-owned managed-key signing boundary used by the AsiBackbone managed-key signing provider.

public interface IManagedKeySigningClient

Remarks

Implementations should call a managed key system, HSM, cloud KMS, or equivalent key-management service without exposing raw private key material to AsiBackbone Core or to this provider package.

Implementations must sign SignatureInput, not SigningHash. Since 6.0 the signature input binds the canonical descriptors, hash, and signing policy context; signing the hash text leaves that context unauthenticated and fails verification.

Methods

SignAsync(ManagedKeySignRequest, CancellationToken)

Signs the governance artifact signature input through a managed-key boundary.

ValueTask<ManagedKeySignResult> SignAsync(ManagedKeySignRequest request, CancellationToken cancellationToken = default)

Parameters

request ManagedKeySignRequest

The managed-key signing request.

cancellationToken CancellationToken

A token used to observe cancellation.

Returns

ValueTask<ManagedKeySignResult>

The managed-key signing result.