Differences
This shows you the differences between two versions of the page.
| Both sides previous revision Previous revision Next revision | Previous revision | ||
| dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-02-image-management:fr-img-005 [2026/07/20 08:43] – ↷ Links adapted because of a move operation nick_dido | dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-02-image-management:fr-img-005 [2026/07/30 05:41] (current) – nick_dido | ||
|---|---|---|---|
| Line 5: | Line 5: | ||
| ===== Statement ===== | ===== Statement ===== | ||
| - | [[dido: | + | [[dido: |
| - | ===== Source Statement | + | ===== Derived From ===== |
| - | > [[dido:99_annexes: | + | This requirement derives from: |
| - | ===== Source ===== | + | * Crucible System Requirements Specification, |
| - | Crucible System Requirements Specification, | + | The Original Requirement states: |
| - | ===== Assessment ===== | + | > // |
| - | The source statement expresses | + | FR-IMG-005 replaces |
| - | The following Specification Discipline and Authoring findings apply: | + | No other substantive normalization |
| - | + | ||
| - | * **The system** does not use the defined system name | + | |
| - | * **shall** does not follow the established uppercase normative convention | + | |
| - | * **Support** | + | |
| - | * **Image verification** does not identify what property of the Image is verified | + | |
| - | * The source statement does not identify the observable result of verification | + | |
| - | * The source statement does not prescribe a signature algorithm, trust store, certificate mechanism, key-management system, or implementation technology | + | |
| - | + | ||
| - | Within the surrounding Image Management requirements, | + | |
| - | + | ||
| - | The normalized Statement: | + | |
| - | + | ||
| - | * Replaces **The system** with [[dido: | + | |
| - | * Replaces **support** with the direct behavior **verify** | + | |
| - | * Identifies the digital signature as the subject of verification | + | |
| - | * Identifies the Image associated with the signature | + | |
| - | * Retains one primary required behavior | + | |
| - | * Preserves implementation independence | + | |
| - | + | ||
| - | The normalized Statement does not independently require vulnerability scanning, compliance assessment, functional testing, Image approval, promotion, or deployment validation. | + | |
| ===== Rationale ===== | ===== Rationale ===== | ||
| - | Verification of the digital signature associated with an identified | + | [[dido: |
| - | + | ||
| - | Signature verification can detect: | + | |
| - | + | ||
| - | * Modification of signed Image content | + | |
| - | * A mismatch between an Image and its signature | + | |
| - | * An invalid signature | + | |
| - | * An unrecognized signing identity | + | |
| - | * A signing identity that does not satisfy the applicable trust conditions | + | |
| - | Image verification contributes to: | + | Verification can identify whether: |
| - | * Image integrity evaluation | + | * The Image differs from the signed representation |
| - | * Image authenticity evaluation | + | * The Digital Signature does not correspond to the identified |
| - | * Controlled Image promotion | + | * The Digital Signature is invalid |
| - | * Controlled Image distribution | + | * The signing identity does not satisfy the applicable trust conditions |
| - | * Controlled Image deployment | + | |
| - | * [[dido: | + | |
| - | * [[dido: | + | |
| - | * [[dido: | + | |
| - | A valid digital signature | + | A valid Digital Signature |
| * Is free from vulnerabilities | * Is free from vulnerabilities | ||
| Line 80: | Line 48: | ||
| * [[dido: | * [[dido: | ||
| + | * [[dido: | ||
| + | * [[dido: | ||
| * [[dido: | * [[dido: | ||
| - | * [[dido: | ||
| - | * [[dido: | ||
| - | * Image identifiers | ||
| - | * Image content digests | ||
| - | * Digital signatures | ||
| - | * Signing identities | ||
| - | * Verification conditions | ||
| - | * Verification operations | ||
| - | * Image repositories | ||
| - | * Image promotion workflows | ||
| - | * [[dido: | ||
| ===== Verification ===== | ===== Verification ===== | ||
| - | - Verification | + | Verification |
| - | - Verification SHALL confirm that Crucible determines whether the evaluated digital signature is valid for the identified Image | + | |
| - | - Verification SHALL confirm that Crucible records the verification result | + | |
| - | Verification may include: | + | |
| - | + | - [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] verifies the associated Digital Signature | |
| - | * Valid-signature testing | + | - Crucible determines whether the Digital Signature is valid for the identified |
| - | * Invalid-signature testing | + | - Crucible produces a verification result |
| - | * Modified-Image testing | + | |
| - | * Image-and-signature mismatch testing | + | |
| - | * Unrecognized-signing-identity testing | + | |
| - | * Signature-record inspection | + | |
| - | * Image-digest comparison | + | |
| - | * Verification-log inspection | + | |
| - | * Automated | + | |
| - | + | ||
| - | The verification record SHALL identify: | + | |
| - | + | ||
| - | - The evaluated Image | + | |
| - | - The Image identifier | + | |
| - | - The evaluated digital signature | + | |
| - | - The applicable verification conditions | + | |
| - | - The verification operation | + | |
| - | - The verification result | + | |
| - | - The observed output | + | |
| - | - The generated | + | |
| - | + | ||
| - | ===== Outgoing Traceability ===== | + | |
| - | + | ||
| - | This requirement realizes: | + | |
| - | + | ||
| - | | + | |
| - | * [[dido:02-crusible: | + | |
| - | * [[dido: | + | |
| - | + | ||
| - | This requirement relates to: | + | |
| - | + | ||
| - | | + | |
| - | * [[dido: | + | |
| - | * [[dido: | + | |
| - | | + | |
| - | * [[dido: | + | |
| - | * [[dido: | + | |
| - | * [[dido: | + | |
| - | * [[dido: | + | |
| ===== Referenced By ===== | ===== Referenced By ===== | ||
| - | The wiki Backlinks function provides the current list of pages that reference | + | The following |
| - | + | ||
| - | Incoming [[dido:99_annexes: | + | |
| - | + | ||
| - | Backlinks identify incoming references but do not define the semantics of each relationship. Referencing pages should identify whether the relationship represents realization, | + | |
| - | + | ||
| - | ===== ConOps Relationship ===== | + | |
| - | + | ||
| - | The Crucible Concept of Operations describes a Phase 1 workflow that builds and processes controlled Image [[dido: | + | |
| - | + | ||
| - | FR-IMG-005 establishes the required digital-signature verification behavior for an identified Image processed by that workflow. | + | |
| - | + | ||
| - | Requirements governing Image building, signing, compliance assessment, promotion, publication, | + | |
| - | + | ||
| - | ===== Delivery Phase ===== | + | |
| - | Phase 1 | + | {{backlinks> |
| ===== Implementation Status ===== | ===== Implementation Status ===== | ||
| - | Not Assessed | + | Implemented |
| - | + | ||
| - | Implementation status requires verification that [[dido: | + | |
| ===== Requirement Status ===== | ===== Requirement Status ===== | ||
| - | Draft | + | < |
| - | + | ||
| - | The source System Requirements Specification identifies Version 1.1 as a draft. | + | |
| ---- | ---- | ||
| - | ===== Notes for Editors | + | ===== Issues |
| - | This requirement page should retain | + | < |
| - | Changes to the Statement SHALL preserve the approved intent | + | < |
| - | The Source Statement should preserve the original wording from the controlling System Requirements Specification. | + | ---- |
| + | ===== Notes for Editors ===== | ||
| - | The Statement should remain limited to verification of the digital signature associated with an identified Image. | + | This requirement page retains |
| - | Requirements for vulnerability scanning, compliance assessment, Image approval, promotion, publication, | + | This page is a leaf requirement |
| - | Verification criteria should test only the behavior stated in the normalized Statement and should not introduce additional normative obligations. | + | The Statement preserves |
| - | Incoming Traceability should use the wiki Backlinks function rather than a manually maintained list. | + | Do not add vulnerability scanning, compliance assessment, Image approval, promotion, publication, |
| To reference this requirement Statement from another wiki page, insert: | To reference this requirement Statement from another wiki page, insert: | ||
| Line 195: | Line 98: | ||
| {{section> | {{section> | ||
| </ | </ | ||
| - | |||
| - | Do not rename this page after an external citation unless a redirect or move plan is in place. | ||
| ---- | ---- | ||