Contribution Date
Contribution Project
Contribution Details
Add a management API for per-tenant C2PA signing identities
The repository and worker were already wired for per-tenant signing
identities (G10-3b), but nothing installed one — so the parked
certificate question had no answer in practice. This mirrors
POST /ai/credentials: GET/POST /signing-identities and
DELETE /signing-identities/active. The private key is validated with the
cert and algorithm (dam_media::provenance::from_pem builds a real signer
and drops it), sealed with the deployment keyring bound to
{tenant}:signing:{id}, and never returned; the certificate is public and
is. Standing an identity down falls back to the deployment identity.
Adds signing_api tests (auth, rejection, list-without-key, stand-down).
Contribution Issue Link
Files count
0
Patches count
1