pub fn verify_seal_with_anchors(
manifest: &[u8],
seal: &[u8],
anchors_der: &[Vec<u8>],
now: u64,
) -> Result<SealVerification>Expand description
Authenticate a seal with a deliberately bounded certificate profile: ECDSA-P256 or ML-DSA signer directly issued by a configured CA anchor, or the configured CA itself. Intermediate paths and extensions whose semantics are not implemented fail closed. This is not general PKIX.