Add a management API for per-tenant C2PA signing identities

Contribution Date
Contribution Project
Contribution Details
Add a management API for per-tenant C2PA signing identities The repository and worker were already wired for per-tenant signing identities (G10-3b), but nothing installed one — so the parked certificate question had no answer in practice. This mirrors POST /ai/credentials: GET/POST /signing-identities and DELETE /signing-identities/active. The private key is validated with the cert and algorithm (dam_media::provenance::from_pem builds a real signer and drops it), sealed with the deployment keyring bound to {tenant}:signing:{id}, and never returned; the certificate is public and is. Standing an identity down falls back to the deployment identity. Adds signing_api tests (auth, rejection, list-without-key, stand-down).
Contribution Author
Bassam Ismail
Files count
0
Patches count
1