oroc update sign
Sign an update manifest and emit a detached manifest.sig file.
Usage#
oroc update sign [--manifest=<path>] (--keys=<file> | --private-key=<hex>) [options]
Options#
| Option | Description |
|---|---|
--manifest=<path> |
path to the manifest JSON file to sign |
--manifest-name=<name> |
manifest filename to use when --manifest is not provided |
--keys=<file> |
JSON file containing a signing key ("privateKey" or "secretKey" field) |
--private-key=<hex> |
Ed25519 private key as a hex string |
--key-id=<id> |
optional key identifier to embed in manifest.sig (default: pk-1) |
--out=<path> |
output path for manifest.sig (default: |
--log-file=<path> |
mirror logs to a JSON file |
Examples#
oroc update sign --keys key.json --manifest manifest.json
# sign manifest.json using the private key in key.json
oroc update sign --private-key <hex-private-key> --manifest manifest.json --out manifest.sig
# sign a manifest using a raw hex private key
Considerations#
- The signature file is JSON containing
schemaVersion,algorithm,keyId, andsignature. - Clients verify exact manifest bytes against
manifest.sigand configured public keys. - Set
ORO_UPDATE_MANIFEST_FILENAMEor pass--manifest-nameto change the default manifest filename.
See also#
Source repository · Edit this page · View Markdown