just_dna_format.signing¶
just_dna_format.signing ¶
Ed25519 signing over artifact.digest (SPEC §5 "future") — the private-key / key-management side.
The artifact digest is already the version's immutable content identity, so signing it — rather than any larger blob — is enough to bind a trusted party's key to the whole file set. A client that pins the marketplace's public key can then detect a digest swapped by a compromised storage backend. Signing is entirely optional and additive: an unsigned manifest verifies exactly as before.
Verification lives in integrity.verify_signature (verification is integrity's job, and keeping
it there avoids an import cycle). Keys are handled as PEM on the private side (what an operator
stores) and as raw base64 on the public side (what travels in the manifest, small and
self-contained).
public_key_b64_from_pem ¶
The base64 raw Ed25519 public key derived from a PEM private key — what a server publishes.
generate_private_key_pem ¶
Generate a fresh Ed25519 private key as unencrypted PKCS#8 PEM (for tests / key bootstrap).
Source code in schema/src/just_dna_format/signing.py
sign_digest ¶
Sign the artifact.digest string with an Ed25519 PEM private key.
The signed message is the digest string's UTF-8 bytes (e.g. b"sha256:9f2c...ab").