Create a signing identity
Associate the appropriate key with the issuer or supported service.
Signing keys
Manage signing identities and retain the public verification information needed to check issued records.
What this means for you
A private signing key creates a signature. The corresponding public key checks it. Keeping their roles separate lets recipients verify evidence without being able to issue records themselves.
New platform signing uses Google Cloud KMS. Public-key availability is essential for checking historical signatures.
From idea to use
Associate the appropriate key with the issuer or supported service.
Give signing permissions only to the services and people that need them.
Retain historical public material and review the effect of revocation and rotation.