DevOps Professional · Module 4: DevSecOps and supply chain · Lab
Verify a Signature with a Local Key, Reject the Wrong Artifact
45 min hands-on · Core
A local machine with signing tools and a locally generated test key; a small test artifact plus a tampered copy. Test keys only, never production keys.
Local guide: run the steps below on your own machine in order, then check the validation list.
Objectives
- Sign a test artifact with a local key
- Verify the good artifact and quote the passing check
- Reject the tampered copy and quote the mismatch
Step 1
Sign the test artifact
Generate a local test key (labeled test-only), sign the fixture artifact, and record the signature alongside it. The key never leaves the lab machine.
Step 2
Verify the good one
Run verification against the untouched artifact and quote the passing result with what was checked (signature, identity, artifact digest).
Step 3
Reject the tampered copy
Verify the tampered copy and quote the failure with the mismatch named. Write why verification must gate deploy, not decorate it.
How to confirm it worked
- Test key labeled test-only, signature recorded
- Passing verification quoted with checked elements
- Tampered copy rejected with the mismatch quoted