AsiBackbone.Signing.LocalDevelopment
2.1.0
Security update available. This version is superseded by AsiBackbone 5.0.0, which addresses published security findings affecting versions through 4.0.0. Upgrade all consumed AsiBackbone.* packages together to 5.0.0. Review the 4.0.0 → 5.0.0 migration guide before deployment, especially if your host persists AsiBackbone enum values as integers, as a data migration may be required. See the repository security advisories and migration documentation for details.
See the version list below for details.
dotnet add package AsiBackbone.Signing.LocalDevelopment --version 2.1.0
NuGet\Install-Package AsiBackbone.Signing.LocalDevelopment -Version 2.1.0
<PackageReference Include="AsiBackbone.Signing.LocalDevelopment" Version="2.1.0" />
<PackageVersion Include="AsiBackbone.Signing.LocalDevelopment" Version="2.1.0" />
<PackageReference Include="AsiBackbone.Signing.LocalDevelopment" />
paket add AsiBackbone.Signing.LocalDevelopment --version 2.1.0
#r "nuget: AsiBackbone.Signing.LocalDevelopment, 2.1.0"
#:package AsiBackbone.Signing.LocalDevelopment@2.1.0
#addin nuget:?package=AsiBackbone.Signing.LocalDevelopment&version=2.1.0
#tool nuget:?package=AsiBackbone.Signing.LocalDevelopment&version=2.1.0
AsiBackbone.Signing.LocalDevelopment
AsiBackbone.Signing.LocalDevelopment provides a local-development RSA signing and verification provider for exercising AsiBackbone signing abstractions without Azure Key Vault, HSM, cloud KMS, certificate-store, or external infrastructure dependencies.
New to AsiBackbone? Start with the concept, not this package: Intent to Execution: An Accountability Pattern and the documentation site. This README covers one package in the family.
Important: This package is intended for local development, samples, and tests. It is not a production managed-key provider and does not provide tamper-evidence, immutability, legal non-repudiation, compliance certification, or protected key custody by itself.
Boundary
This package implements:
IAsiBackboneSigningServiceIAsiBackboneSignatureVerificationService
It signs the SigningRequest.SigningHash value using an in-process RSA key generated for the service instance and returns provider-neutral SigningMetadata.
Core remains provider-neutral. AsiBackbone.Core does not reference this package.
Metadata returned
Successful signing results include:
- signing hash
- hash algorithm
- Base64 signature value
- signature algorithm descriptor
- key ID
- key version
- provider descriptor
- signed UTC timestamp
- local-development warning metadata
Signing failures in normal flow return unsigned signing metadata with explicit signing_status, failure_code, and failure_message values unless the host opts out by setting ReturnUnsignedOnFailure = false.
Example registration
var localSigningOptions = LocalDevelopmentSigningOptions.Create(
keyId: "sample-local-dev-key",
keyVersion: "dev");
var localSigningService = new LocalDevelopmentSigningService(localSigningOptions);
builder.Services.AddSingleton(localSigningService);
builder.Services.AddSingleton<IAsiBackboneSigningService>(localSigningService);
builder.Services.AddSingleton<IAsiBackboneSignatureVerificationService>(localSigningService);
Example flow
AuditLedgerRecord
-> CanonicalPayloadBuilder.ForAuditLedgerRecord(...)
-> CanonicalPayloadHasher.ComputeHash(...)
-> SigningRequest
-> LocalDevelopmentSigningService.SignAsync(...)
-> SignatureVerificationRequest
-> LocalDevelopmentSigningService.VerifyAsync(...)
Non-goals
This package does not:
- integrate with Azure Key Vault, Managed HSM, local machine certificate stores, or cloud KMS services;
- persist private key material;
- provide production key rotation;
- provide legal non-repudiation;
- verify an audit hash chain;
- provide immutable storage or external anchoring;
- make unsigned, signed, or verified records tamper-evident by default.
Use a managed-key or HSM-backed provider for production workflows where signing is part of a security or audit-control boundary.
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net10.0
- AsiBackbone.Core (>= 2.1.0)
- AsiBackbone.DependencyInjection (>= 2.1.0)
NuGet packages
This package is not used by any NuGet packages.
GitHub repositories
This package is not used by any popular GitHub repositories.
| Version | Downloads | Last Updated | |
|---|---|---|---|
| 7.1.0 | 87 | 10/3/2026 | |
| 7.0.0 | 96 | 9/26/2026 | |
| 6.0.0 | 117 | 9/19/2026 | |
| 5.2.0 | 101 | 9/14/2026 | |
| 5.1.0 | 1,362 | 9/12/2026 | |
| 5.0.0 | 123 | 9/7/2026 | |
| 4.0.0 | 131 | 9/6/2026 | |
| 3.2.3 | 136 | 8/30/2026 | |
| 3.2.2 | 137 | 8/22/2026 | |
| 3.2.1 | 157 | 8/7/2026 | |
| 3.2.0 | 147 | 8/2/2026 | |
| 3.1.0 | 153 | 7/20/2026 | |
| 3.0.1 | 150 | 7/14/2026 | |
| 3.0.0 | 168 | 7/13/2026 | |
| 2.3.0 | 163 | 7/6/2026 | |
| 2.2.1 | 156 | 7/3/2026 | |
| 2.2.0 | 156 | 7/1/2026 | |
| 2.1.1 | 152 | 6/29/2026 | |
| 2.1.0 | 157 | 6/28/2026 | |
| 2.0.2 | 188 | 6/26/2026 |