AsiBackbone.Signing.LocalDevelopment
7.1.0
dotnet add package AsiBackbone.Signing.LocalDevelopment --version 7.1.0
NuGet\Install-Package AsiBackbone.Signing.LocalDevelopment -Version 7.1.0
<PackageReference Include="AsiBackbone.Signing.LocalDevelopment" Version="7.1.0" />
<PackageVersion Include="AsiBackbone.Signing.LocalDevelopment" Version="7.1.0" />
<PackageReference Include="AsiBackbone.Signing.LocalDevelopment" />
paket add AsiBackbone.Signing.LocalDevelopment --version 7.1.0
#r "nuget: AsiBackbone.Signing.LocalDevelopment, 7.1.0"
#:package AsiBackbone.Signing.LocalDevelopment@7.1.0
#addin nuget:?package=AsiBackbone.Signing.LocalDevelopment&version=7.1.0
#tool nuget:?package=AsiBackbone.Signing.LocalDevelopment&version=7.1.0
AsiBackbone.Signing.LocalDevelopment
AsiBackbone.Signing.LocalDevelopment provides a local-development RSA signing and verification provider for exercising AsiBackbone signing abstractions without Azure Key Vault, HSM, cloud KMS, certificate-store, or external infrastructure dependencies.
New to AsiBackbone? Start with the concept, not this package: Intent to Execution: An Accountability Pattern and the documentation site. This README covers one package in the family.
Important: This package is intended for local development, samples, and tests. It is not a production managed-key provider and does not provide tamper-evidence, immutability, legal non-repudiation, compliance certification, or protected key custody by itself.
Boundary
This package implements:
IGovernanceSigningServiceIGovernanceSignatureVerificationService
It signs the SigningRequest.SigningHash value using an in-process RSA key generated for the service instance and returns provider-neutral SigningMetadata.
The default local-development signature descriptor is RSASSA-PSS-SHA256-LOCAL-DEV, and the in-process RSA signer uses RSA-PSS with SHA-256. Existing local-development fixtures that assumed the earlier PKCS#1 v1.5 descriptor should be regenerated or configured explicitly for their test-only compatibility path.
Core remains provider-neutral. AsiBackbone.Core does not reference this package.
RSA key size
The generated local-development RSA key defaults to 2048 bits. Explicit values must be at least LocalDevelopmentSigningOptions.MinimumKeySizeBits (currently 2048 bits).
Values below the minimum, including zero and negative values, fail configuration validation. They are not silently replaced with the default. This makes local configuration mistakes visible while preserving the secure default when no key size is supplied.
Supported larger values, such as 3072 or 4096 bits, are passed directly to the platform RSA implementation. Hosts should still use a managed-key or HSM-backed provider for production key custody.
Metadata returned
Successful signing results include:
- signing hash
- hash algorithm
- Base64 signature value
- signature algorithm descriptor
- key ID
- key version
- provider descriptor
- signed UTC timestamp
- local-development warning metadata
Signing failures in normal flow return unsigned signing metadata with explicit signing_status, failure_code, and failure_message values unless the host opts out by setting ReturnUnsignedOnFailure = false.
Example registration
var localSigningOptions = LocalDevelopmentSigningOptions.Create(
keyId: "sample-local-dev-key",
keyVersion: "dev",
keySizeBits: 3072);
var localSigningService = new LocalDevelopmentSigningService(localSigningOptions);
builder.Services.AddSingleton(localSigningService);
builder.Services.AddSingleton<IGovernanceSigningService>(localSigningService);
builder.Services.AddSingleton<IGovernanceSignatureVerificationService>(localSigningService);
The builder facade validates configuration during registration:
builder.Services
.AddAsiBackbone()
.UseLocalDevelopmentSigning(localSigningOptions);
Example flow
AuditLedgerRecord
-> CanonicalPayloadBuilder.ForAuditLedgerRecord(...)
-> CanonicalPayloadHasher.ComputeHash(...)
-> SigningRequest
-> LocalDevelopmentSigningService.SignAsync(...)
-> SignatureVerificationRequest
-> LocalDevelopmentSigningService.VerifyAsync(...)
Non-goals
This package does not:
- integrate with Azure Key Vault, Managed HSM, local machine certificate stores, or cloud KMS services;
- persist private key material;
- provide production key rotation;
- provide legal non-repudiation;
- verify an audit hash chain;
- provide immutable storage or external anchoring;
- make unsigned, signed, or verified records tamper-evident by default.
Use a managed-key or HSM-backed provider for production workflows where signing is part of a security or audit-control boundary.
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net10.0
- AsiBackbone.Core (>= 7.1.0)
- AsiBackbone.DependencyInjection (>= 7.1.0)
NuGet packages
This package is not used by any NuGet packages.
GitHub repositories
This package is not used by any popular GitHub repositories.
| Version | Downloads | Last Updated | |
|---|---|---|---|
| 7.1.0 | 75 | 10/3/2026 | |
| 7.0.0 | 96 | 9/26/2026 | |
| 6.0.0 | 117 | 9/19/2026 | |
| 5.2.0 | 101 | 9/14/2026 | |
| 5.1.0 | 1,361 | 9/12/2026 | |
| 5.0.0 | 123 | 9/7/2026 | |
| 4.0.0 | 131 | 9/6/2026 | |
| 3.2.3 | 136 | 8/30/2026 | |
| 3.2.2 | 136 | 8/22/2026 | |
| 3.2.1 | 157 | 8/7/2026 | |
| 3.2.0 | 147 | 8/2/2026 | |
| 3.1.0 | 153 | 7/20/2026 | |
| 3.0.1 | 150 | 7/14/2026 | |
| 3.0.0 | 168 | 7/13/2026 | |
| 2.3.0 | 163 | 7/6/2026 | |
| 2.2.1 | 156 | 7/3/2026 | |
| 2.2.0 | 156 | 7/1/2026 | |
| 2.1.1 | 152 | 6/29/2026 | |
| 2.1.0 | 157 | 6/28/2026 | |
| 2.0.2 | 188 | 6/26/2026 |