DEV Community
Follow
What Ed25519 Signing Actually Proves About a Test Result
An Ed25519 signature primarily proves that a registered private-key holder signed an evidence record. This signature verifies the act of signing but does not authenticate who approved the result. Ranex uses this to validate evidence against a committed public keyring before admitting records. This binding ensures that evidence is tied to a specific subject and command.However, a signature does not guarantee the truthfulness or accuracy of the reported observations. The approver field is currently an unauthenticated string, meaning a signature offers no proof of the reviewer's identity. Furthermore, even approved dependencies can report incorrect outcomes, and a signature cannot force code to report reality.Private signing keys should be kept securely outside the repository to maintain separation between signing capability and the trust root. This separation prevents an attacker from forging signatures if the repository is compromised. Processes holding private keys are still vulnerable to theft.Known gaps, such as unauthenticated approver identity and same-user key theft, are acknowledged. These risks must be managed alongside the strengths of public-key verification. Stacking complementary controls, like append-only records and distinct gate checks for different properties, enhances overall security. Understanding precisely what a signature proves and doesn't prove is crucial for making defensible claims.