verifier

package
v1.118.1 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 7, 2026 License: Apache-2.0 Imports: 21 Imported by: 0

Documentation

Index

Constants

This section is empty.

Variables

View Source
var (
	// ErrTSAResponseInvalid indicates the RFC3161 timestamp response could not
	// be verified against the TSA certificate chain.
	ErrTSAResponseInvalid = errors.New("TSA response verification failed")

	// ErrTimestampOutsideTSAValidity indicates the timestamp's time falls
	// outside the TSA certificate's NotBefore/NotAfter window.
	ErrTimestampOutsideTSAValidity = errors.New("timestamp outside TSA certificate validity window")

	// ErrSigningCertNotValidAtTimestamp indicates the signing certificate
	// was not valid at the timestamp's time.
	ErrSigningCertNotValidAtTimestamp = errors.New("signing certificate not valid at timestamp time")

	// ErrNoTSARootsConfigured indicates the bundle contains signed timestamps
	// but no TSA trust roots are configured on the server.
	ErrNoTSARootsConfigured = errors.New("no TSA trust roots configured")

	// ErrTSASignerNotTrusted indicates the timestamp was signed by a certificate
	// that belongs to none of the configured timestamp authorities. Upstream TSAs
	// rotate their responder certificates without notice, so this points at a
	// pinned chain that has fallen behind, not at a faulty attestation.
	ErrTSASignerNotTrusted = errors.New("TSA response signer is not a configured timestamp authority")
)
View Source
var ErrInvalidBundle = errors.New("invalid bundle")
View Source
var ErrMissingVerificationMaterial = errors.New("missing material")
View Source
var ErrOrganizationMismatch = errors.New("signing certificate organization mismatch")

ErrOrganizationMismatch indicates the signing certificate was not issued to the expected organization, or does not identify a single organization.

View Source
var ErrUnsupportedVerificationMaterial = errors.New("unsupported verification material")

ErrUnsupportedVerificationMaterial indicates the bundle carries verification material we cannot verify a signature against (e.g. a bare public key with no trusted key set). It is treated as a verification failure, never ignored.

Functions

func IsTrustConfigError added in v1.108.5

func IsTrustConfigError(err error) bool

IsTrustConfigError reports whether err is a timestamp verification failure attributable to the TSA trust configuration rather than to the attestation itself. Such a failure must not reject an incoming attestation: the signature is verified independently, and verification is recomputed on every read, so the outcome self-heals once the configuration catches up with the upstream TSA.

func VerifyBundle

func VerifyBundle(ctx context.Context, bundleBytes []byte, tr *TrustedRoot, opts ...VerifyOption) error

func VerifyTimestamps added in v0.170.0

func VerifyTimestamps(sb *bundle.Bundle, tr *TrustedRoot) error

Types

type TrustedRoot

type TrustedRoot struct {
	// map key identifiers to a chain of certificates
	Keys                 map[string][]*x509.Certificate
	TimestampAuthorities map[string][]*x509.Certificate
}

type VerifyOption added in v1.118.0

type VerifyOption func(*verifyOptions)

func WithExpectedOrganization added in v1.118.0

func WithExpectedOrganization(orgID string) VerifyOption

WithExpectedOrganization requires the signing certificate to be issued to the given organization. Chainloop keyless certificates carry it in the subject Organization field.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL