pub fn verify_seal(
manifest_bytes: &[u8],
seal_bytes: &[u8],
) -> Result<SealVerification>Expand description
Verify a CMS seal against the manifest bytes.
Checks:
- Parses as valid CMS SignedData
- The message-digest signed attribute matches SHA-256(manifest_bytes)
- The signature over the signed attributes is valid (ECDSA P-256)