====== FR-IMG-005 — Image Verification ====== [[dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-02-image-management:start|Go to Crucible Image Management Requirements]] ===== Statement ===== [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] SHALL verify the [[dido:99_annexes:annex-b-terms-and-definitions:d:digital_signature|Digital Signature]] associated with an identified [[dido:99_annexes:annex-b-terms-and-definitions:i:image|Image]]. ===== Derived From ===== This requirement derives from: * Crucible System Requirements Specification, Version 1.1 Draft, Functional Requirements, FR-IMG-005 The Original Requirement states: > //[[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] SHALL perform [[dido:99_annexes:annex-b-terms-and-definitions:d:digital_signature_verification|Digital Signature Verification]] for the [[dido:99_annexes:annex-b-terms-and-definitions:d:digital_signature|Digital Signature]] associated with an identified [[dido:99_annexes:annex-b-terms-and-definitions:i:image|Image]].//[[dido:02-crusible:99-annexes:annex-b:cr-001|[C1]]] FR-IMG-005 replaces the phrase **perform Digital Signature Verification for** with the direct verb **verify** while preserving the subject of the verification and its association with the identified Image. No other substantive normalization is required. ===== Rationale ===== [[dido:99_annexes:annex-b-terms-and-definitions:d:digital_signature_verification|Digital Signature Verification]] determines whether a [[dido:99_annexes:annex-b-terms-and-definitions:d:digital_signature|Digital Signature]] is valid for an identified [[dido:99_annexes:annex-b-terms-and-definitions:i:image|Image]] under the applicable verification conditions. Verification can identify whether: * The Image differs from the signed representation * The Digital Signature does not correspond to the identified Image * The Digital Signature is invalid * The signing identity does not satisfy the applicable trust conditions A valid Digital Signature does not independently establish that the Image: * Is free from vulnerabilities * Satisfies a compliance baseline * Is approved for promotion * Is authorized for deployment * Is compatible with a target platform * Is suitable for a specified purpose Separate requirements govern those determinations. ===== Applies To ===== This requirement applies to: * [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] * [[dido:99_annexes:annex-b-terms-and-definitions:d:digital_signature_verification|Digital Signature Verification]] * [[dido:99_annexes:annex-b-terms-and-definitions:d:digital_signature|Digital Signatures]] * [[dido:99_annexes:annex-b-terms-and-definitions:i:image|Images]] ===== Verification ===== Verification confirms that: - An identified [[dido:99_annexes:annex-b-terms-and-definitions:i:image|Image]] with an associated [[dido:99_annexes:annex-b-terms-and-definitions:d:digital_signature|Digital Signature]] is selected for verification - [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] verifies the associated Digital Signature - Crucible determines whether the Digital Signature is valid for the identified Image - Crucible produces a verification result ===== Referenced By ===== The following pages reference this requirement: {{backlinks>.#dido:02-crusible}} ===== Implementation Status ===== Implemented and Verified ===== Requirement Status ===== Review and approve FR-IMG-005 as a leaf requirement. ---- ===== Issues ===== Determine whether separate requirements define the applicable trust conditions and trusted signing identities. Determine whether separate requirements govern preservation of the Digital Signature Verification result. ---- ===== Notes for Editors ===== This requirement page retains the stable requirement identifier ''FR-IMG-005''. This page is a leaf requirement page and omits a trailing '':start'' from its namespace. The Statement preserves the approved source intent by requiring Crucible to verify the Digital Signature associated with an identified Image. Do not add vulnerability scanning, compliance assessment, Image approval, promotion, publication, transfer, deployment validation, signature-algorithm, trust-store, or key-governance obligations unless the controlling requirement changes through an approved requirements process. To reference this requirement Statement from another wiki page, insert: {{section>dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-02-image-management:fr-img-005#Statement&noheader&nofooter&noeditbtn}} ---- © 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.