RC Rick Collettesecurity · AI · music · people
Concept

Trust Root

concept-trust-root · canon/concepts/trust-root.md

Trust Root. The configured authority anchor a system uses to decide whether a signature, certificate, bundle, package, peer, or artifact should be trusted.

A trust root is not the artifact; it is the authority anchor the signed-artifact gate depends on. Signature verification is only meaningful when the system also knows which authority is allowed to sign for this context.

The trust root answers "who may sign?" The companion unsigned-artifact policy answers "what happens when no acceptable signature exists?"

In a secure fetch boundary, the trust root helps turn network retrieval into a governed admission decision rather than a download followed by hope.

Incoming References

Law 2
Pattern 1