Class ManagedKeySignRequest
- Namespace
- AsiBackbone.Signing.ManagedKey
- Assembly
- AsiBackbone.Signing.ManagedKey.dll
Represents a managed-key client request to sign a precomputed governance artifact hash.
public sealed class ManagedKeySignRequest
- Inheritance
-
ManagedKeySignRequest
- Inherited Members
Constructors
ManagedKeySignRequest(string, string, string, string, string?, string?, IReadOnlyDictionary<string, string>?)
Initializes a new instance of the ManagedKeySignRequest class.
public ManagedKeySignRequest(string signingHash, string hashAlgorithm, string signatureAlgorithm, string keyId, string? keyVersion = null, string? purpose = null, IReadOnlyDictionary<string, string>? metadata = null)
Parameters
signingHashstringhashAlgorithmstringsignatureAlgorithmstringkeyIdstringkeyVersionstringpurposestringmetadataIReadOnlyDictionary<string, string>
Properties
HashAlgorithm
Gets the hash algorithm descriptor associated with SigningHash.
public string HashAlgorithm { get; }
Property Value
KeyId
Gets the managed key identifier or key URI reference.
public string KeyId { get; }
Property Value
KeyVersion
Gets the managed key version, when supplied.
public string? KeyVersion { get; }
Property Value
Metadata
Gets provider-neutral request metadata.
public IReadOnlyDictionary<string, string> Metadata { get; }
Property Value
Purpose
Gets the host-defined signing purpose, when supplied.
public string? Purpose { get; }
Property Value
SignatureAlgorithm
Gets the requested provider-neutral signature algorithm descriptor.
public string SignatureAlgorithm { get; }
Property Value
SignatureInput
Gets the exact bytes the managed key must sign.
public ReadOnlyMemory<byte> SignatureInput { get; init; }
Property Value
Remarks
ManagedKeySigningService copies SignatureInput here. For artifacts signed through GovernanceArtifactSigner this is the version 1 input that binds the canonical descriptors, hash, and signing policy context. Clients must sign these bytes, not SigningHash: pass them as the message to a message-signing API, or hash them with the key's digest algorithm before calling a digest-signing API. A client that signs the hash text produces signatures that fail version 1 verification. When no input was supplied, this returns the pre-6.0 hash-only input. The supplied value is copied.
SigningHash
Gets the precomputed hash to sign.
public string SigningHash { get; }