Skip to main content

Module seal

Module seal 

Source
Expand description

CMS seal verification for ahu bundles.

Verifies the detached CMS SignedData seal over the manifest bytes. This confirms the bundle was produced by a specific signer and has not been tampered with.

Structs§

SealVerification
Result of seal verification.

Functions§

verify_seal
Verify a CMS seal against the manifest bytes.
verify_seal_with_anchors
Authenticate a seal with a deliberately bounded certificate profile: ECDSA-P256 or ML-DSA signer directly issued by a configured CA anchor, or the configured CA itself. Intermediate paths and extensions whose semantics are not implemented fail closed. This is not general PKIX.
verify_seal_with_pins
Authenticate an explicitly pinned end-entity signing certificate. Pins are exact DER certificate matches, not CA trust anchors.