AsiBackbone.Signing.LocalDevelopment 7.1.0

dotnet add package AsiBackbone.Signing.LocalDevelopment --version 7.1.0
                    
NuGet\Install-Package AsiBackbone.Signing.LocalDevelopment -Version 7.1.0
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="AsiBackbone.Signing.LocalDevelopment" Version="7.1.0" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="AsiBackbone.Signing.LocalDevelopment" Version="7.1.0" />
                    
Directory.Packages.props
<PackageReference Include="AsiBackbone.Signing.LocalDevelopment" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add AsiBackbone.Signing.LocalDevelopment --version 7.1.0
                    
#r "nuget: AsiBackbone.Signing.LocalDevelopment, 7.1.0"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package AsiBackbone.Signing.LocalDevelopment@7.1.0
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=AsiBackbone.Signing.LocalDevelopment&version=7.1.0
                    
Install as a Cake Addin
#tool nuget:?package=AsiBackbone.Signing.LocalDevelopment&version=7.1.0
                    
Install as a Cake Tool

AsiBackbone.Signing.LocalDevelopment

AsiBackbone.Signing.LocalDevelopment provides a local-development RSA signing and verification provider for exercising AsiBackbone signing abstractions without Azure Key Vault, HSM, cloud KMS, certificate-store, or external infrastructure dependencies.

New to AsiBackbone? Start with the concept, not this package: Intent to Execution: An Accountability Pattern and the documentation site. This README covers one package in the family.

Important: This package is intended for local development, samples, and tests. It is not a production managed-key provider and does not provide tamper-evidence, immutability, legal non-repudiation, compliance certification, or protected key custody by itself.

Boundary

This package implements:

  • IGovernanceSigningService
  • IGovernanceSignatureVerificationService

It signs the SigningRequest.SigningHash value using an in-process RSA key generated for the service instance and returns provider-neutral SigningMetadata.

The default local-development signature descriptor is RSASSA-PSS-SHA256-LOCAL-DEV, and the in-process RSA signer uses RSA-PSS with SHA-256. Existing local-development fixtures that assumed the earlier PKCS#1 v1.5 descriptor should be regenerated or configured explicitly for their test-only compatibility path.

Core remains provider-neutral. AsiBackbone.Core does not reference this package.

RSA key size

The generated local-development RSA key defaults to 2048 bits. Explicit values must be at least LocalDevelopmentSigningOptions.MinimumKeySizeBits (currently 2048 bits).

Values below the minimum, including zero and negative values, fail configuration validation. They are not silently replaced with the default. This makes local configuration mistakes visible while preserving the secure default when no key size is supplied.

Supported larger values, such as 3072 or 4096 bits, are passed directly to the platform RSA implementation. Hosts should still use a managed-key or HSM-backed provider for production key custody.

Metadata returned

Successful signing results include:

  • signing hash
  • hash algorithm
  • Base64 signature value
  • signature algorithm descriptor
  • key ID
  • key version
  • provider descriptor
  • signed UTC timestamp
  • local-development warning metadata

Signing failures in normal flow return unsigned signing metadata with explicit signing_status, failure_code, and failure_message values unless the host opts out by setting ReturnUnsignedOnFailure = false.

Example registration

var localSigningOptions = LocalDevelopmentSigningOptions.Create(
    keyId: "sample-local-dev-key",
    keyVersion: "dev",
    keySizeBits: 3072);

var localSigningService = new LocalDevelopmentSigningService(localSigningOptions);

builder.Services.AddSingleton(localSigningService);
builder.Services.AddSingleton<IGovernanceSigningService>(localSigningService);
builder.Services.AddSingleton<IGovernanceSignatureVerificationService>(localSigningService);

The builder facade validates configuration during registration:

builder.Services
    .AddAsiBackbone()
    .UseLocalDevelopmentSigning(localSigningOptions);

Example flow

AuditLedgerRecord
  -> CanonicalPayloadBuilder.ForAuditLedgerRecord(...)
  -> CanonicalPayloadHasher.ComputeHash(...)
  -> SigningRequest
  -> LocalDevelopmentSigningService.SignAsync(...)
  -> SignatureVerificationRequest
  -> LocalDevelopmentSigningService.VerifyAsync(...)

Non-goals

This package does not:

  • integrate with Azure Key Vault, Managed HSM, local machine certificate stores, or cloud KMS services;
  • persist private key material;
  • provide production key rotation;
  • provide legal non-repudiation;
  • verify an audit hash chain;
  • provide immutable storage or external anchoring;
  • make unsigned, signed, or verified records tamper-evident by default.

Use a managed-key or HSM-backed provider for production workflows where signing is part of a security or audit-control boundary.

Product Compatible and additional computed target framework versions.
.NET net10.0 is compatible.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

NuGet packages

This package is not used by any NuGet packages.

GitHub repositories

This package is not used by any popular GitHub repositories.