dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-02-image-management:fr-img-005

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revision Previous revision
Next revision
Previous revision
dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-02-image-management:fr-img-005 [2026/07/20 08:43] – ↷ Links adapted because of a move operation nick_didodido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-02-image-management:fr-img-005 [2026/07/30 05:41] (current) nick_dido
Line 5: Line 5:
 ===== Statement ===== ===== Statement =====
  
-[[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] SHALL verify the digital signature associated with an identified [[dido:99_annexes:annex-b-terms-and-definitions:i:image|Image]].+[[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] SHALL verify the [[dido:99_annexes:annex-b-terms-and-definitions:d:digital_signature|Digital Signature]] associated with an identified [[dido:99_annexes:annex-b-terms-and-definitions:i:image|Image]].
  
-===== Source Statement =====+===== Derived From =====
  
-> [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] SHALL perform [[dido:99_annexes:annex-b-terms-and-definitions:d:digital_signature_verification|Digital Signature Verification]] for the [[dido:99_annexes:annex-b-terms-and-definitions:d:digital_signature|Digital Signature]] associated with an identified [[dido:99_annexes:annex-b-terms-and-definitions:i:image|Image]].+This requirement derives from:
  
-===== Source =====+  * Crucible System Requirements Specification, Version 1.1 Draft, Functional Requirements, FR-IMG-005
  
-Crucible System Requirements Specification, Version 1.1 Draft, Functional Requirements, FR-IMG-005.+The Original Requirement states:
  
-===== Assessment =====+> //[[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] SHALL perform [[dido:99_annexes:annex-b-terms-and-definitions:d:digital_signature_verification|Digital Signature Verification]] for the [[dido:99_annexes:annex-b-terms-and-definitions:d:digital_signature|Digital Signature]] associated with an identified [[dido:99_annexes:annex-b-terms-and-definitions:i:image|Image]].//[[dido:02-crusible:99-annexes:annex-b:cr-001|[C1]]]
  
-The source statement expresses the approved intent but does not provide a fully testable formulation.+FR-IMG-005 replaces the phrase **perform Digital Signature Verification for** with the direct verb **verify** while preserving the subject of the verification and its association with the identified Image.
  
-The following Specification Discipline and Authoring findings apply: +No other substantive normalization is required.
- +
-  * **The system** does not use the defined system name +
-  * **shall** does not follow the established uppercase normative convention +
-  * **Support** is a weak verb that does not identify the required behavior +
-  * **Image verification** does not identify what property of the Image is verified +
-  * The source statement does not identify the observable result of verification +
-  * The source statement does not prescribe a signature algorithm, trust store, certificate mechanism, key-management system, or implementation technology +
- +
-Within the surrounding Image Management requirements, FR-IMG-004 establishes Image signing. FR-IMG-005 therefore treats verification as verification of the digital signature associated with an identified Image. +
- +
-The normalized Statement: +
- +
-  * Replaces **The system** with [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] +
-  * Replaces **support** with the direct behavior **verify** +
-  * Identifies the digital signature as the subject of verification +
-  * Identifies the Image associated with the signature +
-  * Retains one primary required behavior +
-  * Preserves implementation independence +
- +
-The normalized Statement does not independently require vulnerability scanning, compliance assessment, functional testing, Image approval, promotion, or deployment validation.+
  
 ===== Rationale ===== ===== Rationale =====
  
-Verification of the digital signature associated with an identified [[dido:99_annexes:annex-b-terms-and-definitions:i:image|Image]] allows [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] to determine whether the signature remains valid for the evaluated Image under the applicable verification conditions. +[[dido:99_annexes:annex-b-terms-and-definitions:d:digital_signature_verification|Digital Signature Verification]] determines whether a [[dido:99_annexes:annex-b-terms-and-definitions:d:digital_signature|Digital Signature]] is valid for an identified [[dido:99_annexes:annex-b-terms-and-definitions:i:image|Image]] under the applicable verification conditions.
- +
-Signature verification can detect: +
- +
-  * Modification of signed Image content +
-  * A mismatch between an Image and its signature +
-  * An invalid signature +
-  * An unrecognized signing identity +
-  * A signing identity that does not satisfy the applicable trust conditions+
  
-Image verification contributes to:+Verification can identify whether:
  
-  * Image integrity evaluation +  * The Image differs from the signed representation 
-  * Image authenticity evaluation +  * The Digital Signature does not correspond to the identified Image 
-  * Controlled Image promotion +  * The Digital Signature is invalid 
-  * Controlled Image distribution +  * The signing identity does not satisfy the applicable trust conditions
-  * Controlled Image deployment +
-  * [[dido:99_annexes:annex-b-terms-and-definitions:a:auditability|Auditability]] +
-  * [[dido:99_annexes:annex-b-terms-and-definitions:e:evidence|Evidence]] +
-  * [[dido:99_annexes:annex-b-terms-and-definitions:t:traceability|Traceability]]+
  
-A valid digital signature does not by itself establish that the Image:+A valid Digital Signature does not independently establish that the Image:
  
   * Is free from vulnerabilities   * Is free from vulnerabilities
Line 80: Line 48:
  
   * [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]]   * [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]]
 +  * [[dido:99_annexes:annex-b-terms-and-definitions:d:digital_signature_verification|Digital Signature Verification]]
 +  * [[dido:99_annexes:annex-b-terms-and-definitions:d:digital_signature|Digital Signatures]]
   * [[dido:99_annexes:annex-b-terms-and-definitions:i:image|Images]]   * [[dido:99_annexes:annex-b-terms-and-definitions:i:image|Images]]
-  * [[dido:99_annexes:annex-b-terms-and-definitions:m:machine_image|Machine Images]] 
-  * [[dido:99_annexes:annex-b-terms-and-definitions:c:container_image|Container Images]] 
-  * Image identifiers 
-  * Image content digests 
-  * Digital signatures 
-  * Signing identities 
-  * Verification conditions 
-  * Verification operations 
-  * Image repositories 
-  * Image promotion workflows 
-  * [[dido:99_annexes:annex-b-terms-and-definitions:c:ci_cd_pipeline|CI/CD Pipelines]] 
  
 ===== Verification ===== ===== Verification =====
  
-  - Verification SHALL confirm that [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] evaluates the digital signature associated with an identified [[dido:99_annexes:annex-b-terms-and-definitions:i:image|Image]] +Verification confirms that:
-  - Verification SHALL confirm that Crucible determines whether the evaluated digital signature is valid for the identified Image +
-  - Verification SHALL confirm that Crucible records the verification result+
  
-Verification may include: +  An identified [[dido:99_annexes:annex-b-terms-and-definitions:i:image|Image]] with an associated [[dido:99_annexes:annex-b-terms-and-definitions:d:digital_signature|Digital Signature]] is selected for verification 
- +  - [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] verifies the associated Digital Signature 
-  * Valid-signature testing +  - Crucible determines whether the Digital Signature is valid for the identified Image 
-  * Invalid-signature testing +  - Crucible produces a verification result
-  * Modified-Image testing +
-  * Image-and-signature mismatch testing +
-  * Unrecognized-signing-identity testing +
-  * Signature-record inspection +
-  * Image-digest comparison +
-  * Verification-log inspection +
-  * Automated [[dido:99_annexes:annex-b-terms-and-definitions:c:ci_cd_pipeline|CI/CD Pipeline]] testing +
- +
-The verification record SHALL identify: +
- +
-  - The evaluated Image +
-  - The Image identifier +
-  - The evaluated digital signature +
-  - The applicable verification conditions +
-  - The verification operation +
-  - The verification result +
-  - The observed output +
-  - The generated [[dido:99_annexes:annex-b-terms-and-definitions:e:evidence|Evidence]] +
- +
-===== Outgoing Traceability ===== +
- +
-This requirement realizes: +
- +
-  * [[dido:02-crusible:99-annexes:annex-c-requirements:01-mission-objectives:mo-001:start|MO-001]] +
-  * [[dido:02-crusible:99-annexes:annex-c-requirements:01-mission-objectives:mo-005:start|MO-005]] +
-  * [[dido:02-crusible:99-annexes:annex-c-requirements:01-mission-objectives:mo-006|MO-006]] +
- +
-This requirement relates to: +
- +
-  * [[dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-02-image-management:fr-img-001|FR-IMG-001 — Build Virtual Machine Images]] +
-  * [[dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-02-image-management:fr-img-002|FR-IMG-002 — Build Container Images]] +
-  * [[dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-02-image-management:fr-img-004|FR-IMG-004 — Image Signing]] +
-  * [[dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-02-image-management:fr-img-006|FR-IMG-006 — Image Promotion Workflows]] +
-  * [[dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-03-deployment-orchestration:fr-dep-007|FR-DEP-007 — Deployment Validation]] +
-  * [[dido:02-crusible:06-machine-images-and-image-layers:start|6. Machine Images and Image Layers]] +
-  * [[dido:02-crusible:09-compliance-and-security:start|9. Compliance and Security]] +
-  * [[dido:02-crusible:10-reproducibility-provenance-and-traceability:start|10. Reproducibility, Provenance, and Traceability]]+
  
 ===== Referenced By ===== ===== Referenced By =====
  
-The wiki Backlinks function provides the current list of pages that reference ''FR-IMG-005''+The following pages reference this requirement:
- +
-Incoming [[dido:99_annexes:annex-b-terms-and-definitions:t:traceability|Traceability]] should be derived dynamically from backlinks rather than maintained as a duplicate manual list. +
- +
-Backlinks identify incoming references but do not define the semantics of each relationship. Referencing pages should identify whether the relationship represents realization, refinement, verification, dependency, or another defined traceability relationship. +
- +
-===== ConOps Relationship ===== +
- +
-The Crucible Concept of Operations describes a Phase 1 workflow that builds and processes controlled Image [[dido:99_annexes:annex-b-terms-and-definitions:a:artifact|Artifacts]] through an automated [[dido:99_annexes:annex-b-terms-and-definitions:c:ci_cd_pipeline|CI/CD Pipeline]]. +
- +
-FR-IMG-005 establishes the required digital-signature verification behavior for an identified Image processed by that workflow. +
- +
-Requirements governing Image building, signing, compliance assessment, promotion, publication, transfer, and deployment define separate behavior. +
- +
-===== Delivery Phase =====+
  
-Phase 1+{{backlinks>.#dido:02-crusible}}
  
 ===== Implementation Status ===== ===== Implementation Status =====
  
-Not Assessed +Implemented and Verified
- +
-Implementation status requires verification that [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] verifies the digital signature associated with an identified [[dido:99_annexes:annex-b-terms-and-definitions:i:image|Image]].+
  
 ===== Requirement Status ===== ===== Requirement Status =====
  
-Draft +<todo>Review and approve FR-IMG-005 as a leaf requirement.</todo>
- +
-The source System Requirements Specification identifies Version 1.1 as a draft.+
  
 ---- ----
-===== Notes for Editors =====+===== Issues =====
  
-This requirement page should retain the stable requirement identifier ''FR-IMG-005''.+<todo>Determine whether separate requirements define the applicable trust conditions and trusted signing identities.</todo>
  
-Changes to the Statement SHALL preserve the approved intent of the source requirement.+<todo>Determine whether separate requirements govern preservation of the Digital Signature Verification result.</todo>
  
-The Source Statement should preserve the original wording from the controlling System Requirements Specification.+---- 
 +===== Notes for Editors =====
  
-The Statement should remain limited to verification of the digital signature associated with an identified Image.+This requirement page retains the stable requirement identifier ''FR-IMG-005''.
  
-Requirements for vulnerability scanning, compliance assessment, Image approval, promotion, publication, transfer, and deployment validation should remain in their applicable requirement pages.+This page is a leaf requirement page and omits a trailing '':start'' from its namespace.
  
-Verification criteria should test only the behavior stated in the normalized Statement and should not introduce additional normative obligations.+The Statement preserves the approved source intent by requiring Crucible to verify the Digital Signature associated with an identified Image.
  
-Incoming Traceability should use the wiki Backlinks function rather than a manually maintained list.+Do not add vulnerability scanning, compliance assessment, Image approval, promotion, publication, transfer, deployment validation, signature-algorithm, trust-store, or key-governance obligations unless the controlling requirement changes through an approved requirements process.
  
 To reference this requirement Statement from another wiki page, insert: To reference this requirement Statement from another wiki page, insert:
Line 195: Line 98:
 {{section>dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-02-image-management:fr-img-005#Statement&noheader&nofooter&noeditbtn}} {{section>dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-02-image-management:fr-img-005#Statement&noheader&nofooter&noeditbtn}}
 </code> </code>
- 
-Do not rename this page after an external citation unless a redirect or move plan is in place. 
  
 ---- ----
  • dido/02-crusible/99-annexes/annex-c-requirements/03-functional-requirements/03-02-image-management/fr-img-005.1784562196.txt.gz
  • Last modified: 2026/07/20 08:43
  • by nick_dido