Differences
This shows you the differences between two versions of the page.
| Next revision | Previous revision | ||
| dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-02-image-management:fr-img-004 [2026/07/17 08:34] – created nick_dido | dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-02-image-management:fr-img-004 [2026/07/30 05:40] (current) – nick_dido | ||
|---|---|---|---|
| Line 5: | Line 5: | ||
| ===== Statement ===== | ===== Statement ===== | ||
| - | [[dido: | + | [[dido: |
| - | ===== Source Statement | + | ===== Derived From ===== |
| - | > The system shall support image signing. | + | This requirement derives from: |
| - | ===== Source ===== | + | * Crucible System Requirements Specification, |
| - | Crucible System Requirements Specification, | + | The Original Requirement states: |
| - | ===== Assessment ===== | + | > // |
| - | The source statement expresses | + | FR-IMG-004 removes |
| - | The following Specification, | + | No other substantive normalization |
| - | + | ||
| - | * **The system** does not use the defined system name | + | |
| - | * **shall** does not follow the established uppercase normative convention | + | |
| - | * **Support** | + | |
| - | * **Image signing** does not identify the Image to which the signature applies | + | |
| - | * The source statement does not identify the observable result of the signing operation | + | |
| - | * The source statement does not require verification of the resulting signature | + | |
| - | * The source statement does not prescribe a signing algorithm, signature format, key-management system, repository, or implementation technology | + | |
| - | + | ||
| - | The normalized Statement: | + | |
| - | + | ||
| - | * Replaces **The system** with [[dido: | + | |
| - | * Replaces **support** with the direct behavior **associate** | + | |
| - | * Identifies an Image as the subject of the signing operation | + | |
| - | * Identifies a digital signature associated with the Image as the required result | + | |
| - | * Retains one primary required behavior | + | |
| - | * Preserves implementation independence | + | |
| - | + | ||
| - | The normalized Statement does not add requirements for signature verification, | + | |
| ===== Rationale ===== | ===== Rationale ===== | ||
| - | A digital signature associated with an identified | + | [[dido: |
| - | + | ||
| - | Image signing contributes to: | + | |
| - | + | ||
| - | * Image authenticity evaluation | + | |
| - | * Image integrity evaluation | + | |
| - | * Identification of the signing identity | + | |
| - | * Controlled Image distribution | + | |
| - | * Controlled Image promotion | + | |
| - | * [[dido: | + | |
| - | * [[dido: | + | |
| - | * [[dido: | + | |
| - | + | ||
| - | The signing operation may apply to: | + | |
| - | * A [[dido: | + | The association allows a separate verification process to determine whether the Digital Signature corresponds to the identified |
| - | * A [[dido: | + | |
| - | * Identifying Image metadata | + | |
| - | * An Image content digest | + | |
| - | * A representation containing | + | |
| - | The applicable architecture | + | This requirement governs generation |
| ===== Applies To ===== | ===== Applies To ===== | ||
| Line 70: | Line 34: | ||
| * [[dido: | * [[dido: | ||
| + | * [[dido: | ||
| * [[dido: | * [[dido: | ||
| - | * [[dido: | + | * [[dido: |
| - | * [[dido: | + | |
| - | * Image identifiers | + | |
| - | * Image content digests | + | |
| - | * Digital | + | |
| - | * Signing identities | + | |
| - | * Signing operations | + | |
| - | * Image repositories | + | |
| - | * Image build workflows | + | |
| - | * Image promotion workflows | + | |
| - | * [[dido: | + | |
| ===== Verification ===== | ===== Verification ===== | ||
| - | - Verification | + | Verification |
| - | - Verification SHALL confirm that the signing operation associates a digital signature with the identified Image | + | |
| - | - Verification SHALL confirm that the associated digital signature identifies or references the Image to which it applies | + | |
| - | Verification may include: | + | |
| - | + | - [[dido: | |
| - | * Machine Image signing tests | + | - Crucible associates the generated Digital Signature with the identified |
| - | * Container Image signing tests | + | - The associated Digital Signature identifies or references the Image to which it applies |
| - | * Signature-record inspection | + | |
| - | * Image-metadata inspection | + | |
| - | * Image-digest comparison | + | |
| - | * Signing-log inspection | + | |
| - | * Automated | + | |
| - | + | ||
| - | The verification record SHALL identify: | + | |
| - | + | ||
| - | - The signed Image | + | |
| - | - The Image identifier | + | |
| - | - The signed representation | + | |
| - | - The signing | + | |
| - | - The associated digital signature | + | |
| - | - The signing result | + | |
| - | - The observed output | + | |
| - | - The generated | + | |
| - | + | ||
| - | ===== Outgoing Traceability ===== | + | |
| - | + | ||
| - | This requirement realizes: | + | |
| - | + | ||
| - | * [[dido: | + | |
| - | * [[dido:02-crusible: | + | |
| - | * [[dido:02-crusible: | + | |
| - | + | ||
| - | This requirement relates to: | + | |
| - | + | ||
| - | * [[dido: | + | |
| - | * [[dido: | + | |
| - | * [[dido: | + | |
| - | * [[dido: | + | |
| - | | + | |
| - | | + | |
| - | * [[dido: | + | |
| - | * [[dido: | + | |
| ===== Referenced By ===== | ===== Referenced By ===== | ||
| - | The wiki Backlinks function provides the current list of pages that reference | + | The following |
| - | Incoming [[dido:99_annexes: | + | {{backlinks> |
| - | Backlinks identify incoming references but do not define the semantics of each relationship. Referencing pages should identify whether the relationship represents realization, | + | ===== Implementation Status ===== |
| - | ===== ConOps Relationship ===== | + | Implemented and Verified |
| - | The Crucible Concept of Operations describes a Phase 1 workflow that builds controlled Image [[dido: | + | ===== Requirement Status ===== |
| - | FR-IMG-004 | + | < |
| - | Requirements governing Image building, signature verification, | + | ---- |
| + | ===== Issues ===== | ||
| - | ===== Delivery Phase ===== | + | < |
| - | Phase 1 | + | < |
| - | + | ||
| - | ===== Implementation Status ===== | + | |
| - | + | ||
| - | Not Assessed | + | |
| - | + | ||
| - | Implementation status requires verification that [[dido: | + | |
| - | + | ||
| - | ===== Requirement Status ===== | + | |
| - | + | ||
| - | Draft | + | |
| - | + | ||
| - | The source System Requirements Specification identifies Version 1.1 as a draft. | + | |
| ---- | ---- | ||
| ===== Notes for Editors ===== | ===== Notes for Editors ===== | ||
| - | This requirement page should retain | + | This requirement page retains |
| - | Changes to the Statement SHALL preserve the approved intent of the source | + | This page is a leaf requirement |
| - | The Source | + | The Statement |
| - | The Statement should remain limited to associating | + | * Generation of a Digital Signature for an identified Image |
| + | * Association of the generated Digital Signature with that Image | ||
| - | Requirements for signature verification, | + | Do not reduce the Statement to association alone because doing so would omit the required generation of the Digital Signature. |
| - | Verification criteria should test only the behavior stated in the normalized Statement and should | + | Do not add signature verification, |
| - | + | ||
| - | Incoming Traceability should use the wiki Backlinks function rather than a manually maintained list. | + | |
| To reference this requirement Statement from another wiki page, insert: | To reference this requirement Statement from another wiki page, insert: | ||
| Line 183: | Line 89: | ||
| {{section> | {{section> | ||
| </ | </ | ||
| - | |||
| - | Do not rename this page after an external citation unless a redirect or move plan is in place. | ||
| ---- | ---- | ||