Interface IManagedKeySigningClient
- Namespace
- AsiBackbone.Signing.ManagedKey
- Assembly
- AsiBackbone.Signing.ManagedKey.dll
Defines the host-owned managed-key signing boundary used by the AsiBackbone managed-key signing provider.
public interface IManagedKeySigningClient
Remarks
Implementations should call a managed key system, HSM, cloud KMS, or equivalent key-management service without exposing raw private key material to AsiBackbone Core or to this provider package.
Implementations must sign SignatureInput, not SigningHash. Since 6.0 the signature input binds the canonical descriptors, hash, and signing policy context; signing the hash text leaves that context unauthenticated and fails verification.
Methods
SignAsync(ManagedKeySignRequest, CancellationToken)
Signs the governance artifact signature input through a managed-key boundary.
ValueTask<ManagedKeySignResult> SignAsync(ManagedKeySignRequest request, CancellationToken cancellationToken = default)
Parameters
requestManagedKeySignRequestThe managed-key signing request.
cancellationTokenCancellationTokenA token used to observe cancellation.
Returns
- ValueTask<ManagedKeySignResult>
The managed-key signing result.