Context Fabric ApplianceRelease verification
SIGNED CHECKSUM MANIFEST

CFA protected bundle verification

Use this page as the public trust-root reference for controlled CFA evaluation bundles. Compare the public key in your zip with the key published here, then verify the Ed25519 signature over CHECKSUMS.sha256 before running the bundle.

Pinned DER/SPKI SHA-256 fingerprint f36cbd57c65437abd795aff0330b94b84b692f33d2bf3962f713c80218ac7840
Manifest

Checksums

After extracting the bundle, run the checksum manifest against every packaged file.

Download CHECKSUMS.sha256

Verification sequence

  1. Extract the protected evaluation zip into a fresh directory.
  2. Compare the included release-ed25519-public.pem against this public key endpoint.
  3. Check the public-key fingerprint against the pinned value on this page.
  4. Verify CHECKSUMS.sha256.sig over CHECKSUMS.sha256.
  5. Run shasum -a 256 -c CHECKSUMS.sha256 inside the extracted bundle.
  6. Use the bundled VERIFY.md for the authoritative offline command transcript.
Boundary: These artifacts prove release integrity for protected evaluation bundles. They do not claim Apple notarization, marketplace certification, production appliance readiness, or legal compliance certification.