====== FR-IMG-004 — Image Signing ====== [[dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-02-image-management:start|Go to Crucible Image Management Requirements]] ===== Statement ===== [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] SHALL generate a [[dido:99_annexes:annex-b-terms-and-definitions:d:digital_signature|Digital Signature]] for an identified [[dido:99_annexes:annex-b-terms-and-definitions:i:image|Image]] and associate the Digital Signature with that Image. ===== Derived From ===== This requirement derives from: * Crucible System Requirements Specification, Version 1.1 Draft, Functional Requirements, FR-IMG-004 The Original Requirement states: > //[[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] SHALL perform [[dido:99_annexes:annex-b-terms-and-definitions:i:image_signing|Image Signing]] by generating a [[dido:99_annexes:annex-b-terms-and-definitions:d:digital_signature|Digital Signature]] for an identified [[dido:99_annexes:annex-b-terms-and-definitions:i:image|Image]] and associating the Digital Signature with that Image.//[[dido:02-crusible:99-annexes:annex-b:cr-001|[C1]]] FR-IMG-004 removes the introductory phrase **perform Image Signing by** while preserving the required signing behavior and results. No other substantive normalization is required. ===== Rationale ===== [[dido:99_annexes:annex-b-terms-and-definitions:i:image_signing|Image Signing]] associates an identified [[dido:99_annexes:annex-b-terms-and-definitions:i:image|Image]] with a [[dido:99_annexes:annex-b-terms-and-definitions:d:digital_signature|Digital Signature]] generated for that Image. The association allows a separate verification process to determine whether the Digital Signature corresponds to the identified Image and the applicable signing identity. This requirement governs generation and association of the Digital Signature. Separate requirements govern signature verification, Image approval, promotion, publication, transfer, and deployment. ===== Applies To ===== This requirement applies to: * [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] * [[dido:99_annexes:annex-b-terms-and-definitions:i:image_signing|Image Signing]] * [[dido:99_annexes:annex-b-terms-and-definitions:i:image|Images]] * [[dido:99_annexes:annex-b-terms-and-definitions:d:digital_signature|Digital Signatures]] ===== Verification ===== Verification confirms that: - An identified [[dido:99_annexes:annex-b-terms-and-definitions:i:image|Image]] is selected for signing - [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] generates a [[dido:99_annexes:annex-b-terms-and-definitions:d:digital_signature|Digital Signature]] for the identified Image - Crucible associates the generated Digital Signature with the identified Image - The associated Digital Signature identifies or references the Image to which it applies ===== Referenced By ===== The following pages reference this requirement: {{backlinks>.#dido:02-crusible}} ===== Implementation Status ===== Implemented and Verified ===== Requirement Status ===== Review and approve FR-IMG-004 as a leaf requirement. ---- ===== Issues ===== Confirm that the Source Statement reproduces the exact wording of the controlling System Requirements Specification. Determine whether separate requirements define the signing identity and signing-key requirements. ---- ===== Notes for Editors ===== This requirement page retains the stable requirement identifier ''FR-IMG-004''. This page is a leaf requirement page and omits a trailing '':start'' from its namespace. The Statement preserves both required results expressed by the Original Requirement: * Generation of a Digital Signature for an identified Image * Association of the generated Digital Signature with that Image Do not reduce the Statement to association alone because doing so would omit the required generation of the Digital Signature. Do not add signature verification, Image approval, promotion, publication, transfer, deployment, signing-algorithm, or key-governance obligations unless the controlling requirement changes through an approved requirements process. To reference this requirement Statement from another wiki page, insert: {{section>dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-02-image-management:fr-img-004#Statement&noheader&nofooter&noeditbtn}} ---- © 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.