Table of Contents

Class ManagedKeySignRequest

Namespace
AsiBackbone.Signing.ManagedKey
Assembly
AsiBackbone.Signing.ManagedKey.dll

Represents a managed-key client request to sign a precomputed governance artifact hash.

public sealed class ManagedKeySignRequest
Inheritance
ManagedKeySignRequest
Inherited Members

Constructors

ManagedKeySignRequest(string, string, string, string, string?, string?, IReadOnlyDictionary<string, string>?)

Initializes a new instance of the ManagedKeySignRequest class.

public ManagedKeySignRequest(string signingHash, string hashAlgorithm, string signatureAlgorithm, string keyId, string? keyVersion = null, string? purpose = null, IReadOnlyDictionary<string, string>? metadata = null)

Parameters

signingHash string
hashAlgorithm string
signatureAlgorithm string
keyId string
keyVersion string
purpose string
metadata IReadOnlyDictionary<string, string>

Properties

HashAlgorithm

Gets the hash algorithm descriptor associated with SigningHash.

public string HashAlgorithm { get; }

Property Value

string

KeyId

Gets the managed key identifier or key URI reference.

public string KeyId { get; }

Property Value

string

KeyVersion

Gets the managed key version, when supplied.

public string? KeyVersion { get; }

Property Value

string

Metadata

Gets provider-neutral request metadata.

public IReadOnlyDictionary<string, string> Metadata { get; }

Property Value

IReadOnlyDictionary<string, string>

Purpose

Gets the host-defined signing purpose, when supplied.

public string? Purpose { get; }

Property Value

string

SignatureAlgorithm

Gets the requested provider-neutral signature algorithm descriptor.

public string SignatureAlgorithm { get; }

Property Value

string

SignatureInput

Gets the exact bytes the managed key must sign.

public ReadOnlyMemory<byte> SignatureInput { get; init; }

Property Value

ReadOnlyMemory<byte>

Remarks

ManagedKeySigningService copies SignatureInput here. For artifacts signed through GovernanceArtifactSigner this is the version 1 input that binds the canonical descriptors, hash, and signing policy context. Clients must sign these bytes, not SigningHash: pass them as the message to a message-signing API, or hash them with the key's digest algorithm before calling a digest-signing API. A client that signs the hash text produces signatures that fail version 1 verification. When no input was supplied, this returns the pre-6.0 hash-only input. The supplied value is copied.

SigningHash

Gets the precomputed hash to sign.

public string SigningHash { get; }

Property Value

string