The most detailed free FDE + DevOps library: 140+ lessons, 70+ labs and 80 long-form articles, in English and Turkish. Start learning →

DevOps Professional · Module 4: DevSecOps and supply chain · Lab

Verify a Signature with a Local Key, Reject the Wrong Artifact

45 min hands-on · Core

A local machine with signing tools and a locally generated test key; a small test artifact plus a tampered copy. Test keys only, never production keys.

Local guide: run the steps below on your own machine in order, then check the validation list.

Objectives

  • Sign a test artifact with a local key
  • Verify the good artifact and quote the passing check
  • Reject the tampered copy and quote the mismatch
  1. Step 1

    Sign the test artifact

    Generate a local test key (labeled test-only), sign the fixture artifact, and record the signature alongside it. The key never leaves the lab machine.

  2. Step 2

    Verify the good one

    Run verification against the untouched artifact and quote the passing result with what was checked (signature, identity, artifact digest).

  3. Step 3

    Reject the tampered copy

    Verify the tampered copy and quote the failure with the mismatch named. Write why verification must gate deploy, not decorate it.

How to confirm it worked

  • Test key labeled test-only, signature recorded
  • Passing verification quoted with checked elements
  • Tampered copy rejected with the mismatch quoted