TapeNow

独立验证发布回执

回执证明归档文件与某个 Ed25519 公钥签署的记录一致。它不自动证明网站当前在线、业务数据库正确或有人独立审计过。

  1. 从部署详情下载发布归档并解压。保留 release.json 和 site 文件夹。
  2. 通过你信任的独立渠道确认签发公钥指纹。指纹是公钥 SPKI DER 的 SHA-256,64 位十六进制;不能仅信回执附带的公钥。
  3. 获取公开公钥注册表并保存为 keys.json。注册表提供当前、历史和撤销状态。离线副本只反映下载时的状态,请在重要核验前更新。
  4. 保存verify-release.mjs与receipt-keys.mjs到同一目录。工具只使用 Node.js 内置模块,不联网。
  5. 运行下方命令,替换指纹为你独立确认的值。
node verify-release.mjs release.json keys.json 你的64位公钥指纹 ./site

成功时返回 verified: true 和文件数量。替换公钥、改文件、签名损坏、撤销公钥都会失败。历史回执没有 keyId 也能使用固定公钥核验。不要把从同一归档提取的指纹直接当可信来源。

轮换与撤销

这一版保留原有签名密钥,没有轮换生产私钥。维护者以后轮换时,须先备份新旧密钥,将旧公钥以 retired 加入注册表,发布新指纹并通知核验方;泄漏密钥标记 revoked。旧回执仍使用原公钥核验。维护者配置 SIGNING_KEY_HISTORY 控制历史记录,普通项目成员不能修改。

← TapeNow

Independently verify a release receipt

A receipt shows that archived files match a record signed by an Ed25519 public key. It does not automatically prove the website is currently online, its business database is correct, or an independent audit occurred.

  1. Download and unpack the archive from deployment details. Keep release.json and the site directory.
  2. Confirm the issuer's public-key fingerprint through an independent channel you trust. It is the SHA-256 of the SPKI DER public key, encoded as 64 hexadecimal characters. Do not trust only the key bundled with the receipt.
  3. Download the public-key registry as keys.json. It records current, retired, and revoked keys. Offline copies reflect their download time; refresh before important verification.
  4. Save verify-release.mjs and receipt-keys.mjs together. They use only built-in Node.js modules and make no network requests.
  5. Run the command below with the independently confirmed fingerprint.
node verify-release.mjs release.json keys.json YOUR_64_HEX_KEY_FINGERPRINT ./site

Success returns verified: true and a file count. Replaced keys, changed files, invalid signatures, and revoked keys fail verification. Historical receipts without keyId can still be checked against a pinned key. A fingerprint copied from the same archive is not an independent trust source.

Rotation and revocation

This version retains the original signing key; the production private key has not been rotated. Before future rotation, operators must back up both keys, add the previous key as retired, publish the new fingerprint, and notify verifiers. Compromised keys are marked revoked. Old receipts are verified with their original public key. Operators control history through SIGNING_KEY_HISTORY; ordinary project members cannot change it.