dido:99_annexes:annex-b-terms-and-definitions:i:image_verification

Image Verification

Image Verification is the process of determining whether a Machine Image satisfies specified identity, integrity, authenticity, provenance, compatibility, or approval criteria.

The process may compare cryptographic digests, validate digital signatures, inspect an Image Record, confirm source revisions, evaluate provenance, check provider registration, or compare image characteristics with declared requirements.

Image Verification may occur after a build, before upload, after provider conversion, before promotion, before deployment, or after transfer across an Air Gap.

Within Crucible, Image Verification supports controlled image lifecycle management and helps ensure that a deployment uses the intended image artifact.

process of determining whether a machine image satisfies specified identity, integrity, authenticity, provenance, compatibility, or approval criteria

Generalized from artifact verification, digital-signature validation, configuration management, software supply-chain security, and machine-image governance usage and specialized for the Crucible architecture and operational model.

Image Verification evaluates specified criteria. It does not imply that every possible security, compliance, operational, or functional property has been evaluated.

Verification of a signature establishes only the properties supported by the applicable signature, certificate, key, and trust policy.

Before deploying a Red Hat Enterprise Linux (RHEL) 9 Capability Image, Crucible verifies its digest, validates its signature, confirms its recorded source revisions, and checks that its Image Record satisfies the deployment’s Image Requirements.


© 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.

  • dido/99_annexes/annex-b-terms-and-definitions/i/image_verification.txt
  • Last modified: 2026/07/18 12:33
  • by 127.0.0.1