com.eruces.teagent.ReleaseManifest
The ReleaseManifest class reads a signed RELEASE MANIFEST: the evidence a client build presents to the Key Service to be admitted on a connection (TE81-264 (ADR 0143)).
The manifest is the bundle manifest the packaging already writes, BUNDLE-MANIFEST.txt: a header of key : value lines, among them artifact : <id>, ended by the FILES line, then one line per file. Beside it, <manifest>.sig holds the raw detached signature over the manifest's EXACT bytes and <manifest>.cert.pem the signer certificate (packaging/te-release-sign.mjs writes both). The digest presented is the SHA-256 of the manifest file's exact bytes – nothing is normalized, so a single changed byte is a different release.
Everything here is read from disk each time it is asked for; nothing is cached, so an attestation always presents the files as they are when the connection opens.
Since: 8.1.0
© Pi Soft, 2018-2026 · Tricryption Engine 8.1
Static Public Attributes
| Type | Name | Description |
|---|---|---|
| final String | SYSTEM_PROPERTY | The system property naming this build's release manifest. |
| final String | SIGNATURE_SUFFIX | Suffix of the detached signature file beside the manifest. |
| final String | CERTIFICATE_SUFFIX | Suffix of the signer certificate file (PEM) beside the manifest. |
Static Public Member Functions
| Member | Description |
|---|---|
ReleaseManifest read(File manifest) | Read a release manifest: its exact bytes, their SHA-256, and the artifact id from its header. |
byte[] certificateDer(File file) | Read one X.509 certificate from a file, PEM or DER, and return it DER-encoded. |
Public Member Functions
| Member | Description |
|---|---|
File getFile() | The manifest file. |
String getArtifactId() | The artifact id from the manifest header. |
byte[] getDigest() | The SHA-256 of the manifest's exact bytes (a copy, 32 bytes). |
byte[] readSignature() | Read the detached signature beside the manifest (<manifest>.sig). |
byte[] readSignerCertificate() | Read the signer certificate beside the manifest (<manifest>.cert.pem). |
Member Function Documentation
ReleaseManifest read(File manifest)
Read a release manifest: its exact bytes, their SHA-256, and the artifact id from its header.
Parameters
| Parameter | Description |
|---|---|
manifest | The manifest file. |
Exceptions
| Exception | Description |
|---|---|
IOException | naming the refusal: the file is missing or unreadable, or its header carries no artifact : line. |
Returns: the manifest.
byte[] certificateDer(File file)
Read one X.509 certificate from a file, PEM or DER, and return it DER-encoded.
Parameters
| Parameter | Description |
|---|---|
file | The certificate file. |
Exceptions
| Exception | Description |
|---|---|
IOException | naming the refusal. |
Returns: the DER encoding.
File getFile()
The manifest file.
String getArtifactId()
The artifact id from the manifest header.
byte[] getDigest()
The SHA-256 of the manifest's exact bytes (a copy, 32 bytes).
byte[] readSignature()
Read the detached signature beside the manifest (<manifest>.sig).
Exceptions
| Exception | Description |
|---|---|
IOException | naming the refusal: the file is missing, unreadable or empty. |
Returns: the raw signature bytes.
byte[] readSignerCertificate()
Read the signer certificate beside the manifest (<manifest>.cert.pem).
Exceptions
| Exception | Description |
|---|---|
IOException | naming the refusal: the file is missing, or is not an X.509 certificate. |
Returns: the certificate, DER-encoded.