Invalid Signature Algorithm

See how v0.2 validation rejects a manifest with a non-Ed25519 signature algorithm. Two entities: a publisher sends and a verifier rejects.

Manifest Publisher

Publishes a v0.2 manifest with an unsupported signature algorithm.

SITE

Algorithm Verifier

Enforces the Ed25519-only algorithm requirement for v0.2 signatures.

CONSUMER
Subject: A v0.2 manifest using Ed448 instead of the required Ed25519.
5 steps