Skip to main content

com.eruces.teagent.ReleaseManifest

The ReleaseManifest class reads a signed RELEASE MANIFEST: the evidence a client build presents to the Key Service to be admitted on a connection (TE81-264 (ADR 0143)).

The manifest is the bundle manifest the packaging already writes, BUNDLE-MANIFEST.txt: a header of key : value lines, among them artifact : <id>, ended by the FILES line, then one line per file. Beside it, <manifest>.sig holds the raw detached signature over the manifest's EXACT bytes and <manifest>.cert.pem the signer certificate (packaging/te-release-sign.mjs writes both). The digest presented is the SHA-256 of the manifest file's exact bytes – nothing is normalized, so a single changed byte is a different release.

Everything here is read from disk each time it is asked for; nothing is cached, so an attestation always presents the files as they are when the connection opens.

Since: 8.1.0

© Pi Soft, 2018-2026 · Tricryption Engine 8.1

Static Public Attributes​

TypeNameDescription
final StringSYSTEM_PROPERTYThe system property naming this build's release manifest.
final StringSIGNATURE_SUFFIXSuffix of the detached signature file beside the manifest.
final StringCERTIFICATE_SUFFIXSuffix of the signer certificate file (PEM) beside the manifest.

Static Public Member Functions​

MemberDescription
ReleaseManifest read(File manifest)Read a release manifest: its exact bytes, their SHA-256, and the artifact id from its header.
byte[] certificateDer(File file)Read one X.509 certificate from a file, PEM or DER, and return it DER-encoded.

Public Member Functions​

MemberDescription
File getFile()The manifest file.
String getArtifactId()The artifact id from the manifest header.
byte[] getDigest()The SHA-256 of the manifest's exact bytes (a copy, 32 bytes).
byte[] readSignature()Read the detached signature beside the manifest (<manifest>.sig).
byte[] readSignerCertificate()Read the signer certificate beside the manifest (<manifest>.cert.pem).

Member Function Documentation​

ReleaseManifest read(File manifest)​

Read a release manifest: its exact bytes, their SHA-256, and the artifact id from its header.

Parameters

ParameterDescription
manifestThe manifest file.

Exceptions

ExceptionDescription
IOExceptionnaming the refusal: the file is missing or unreadable, or its header carries no artifact : line.

Returns: the manifest.

byte[] certificateDer(File file)​

Read one X.509 certificate from a file, PEM or DER, and return it DER-encoded.

Parameters

ParameterDescription
fileThe certificate file.

Exceptions

ExceptionDescription
IOExceptionnaming the refusal.

Returns: the DER encoding.

File getFile()​

The manifest file.

String getArtifactId()​

The artifact id from the manifest header.

byte[] getDigest()​

The SHA-256 of the manifest's exact bytes (a copy, 32 bytes).

byte[] readSignature()​

Read the detached signature beside the manifest (<manifest>.sig).

Exceptions

ExceptionDescription
IOExceptionnaming the refusal: the file is missing, unreadable or empty.

Returns: the raw signature bytes.

byte[] readSignerCertificate()​

Read the signer certificate beside the manifest (<manifest>.cert.pem).

Exceptions

ExceptionDescription
IOExceptionnaming the refusal: the file is missing, or is not an X.509 certificate.

Returns: the certificate, DER-encoded.