SYSE.32:4.4 - Apply the exact authenticity Method when that claim is required
Use SLSA v1.2, Verifying artifacts with the consumer’s configured trust roots and expectations. Its operative verification includes the signature, the actual artifact’s correspondence to the provenance subject, the expected provenance type, and the recognized builder’s trust basis. Compare the claimed build with the expected builder, canonical source, build type and external parameters; a valid signature alone is insufficient.
Supply those expectations through the actual authorized trust arrangement. Unknown or unexpected parameters require the source Method’s explicit disposition, not silent acceptance. Use a verifier qualified for the deployed formats and trust system.
Distinguish missing provenance, invalid verification, an unexpected but correctly signed build, and unavailable verification. Each may require a different investigation or authorized exception decision, but none establishes the missing trust claim. If an authorized holder permits a bounded use without that assurance, retain the limitation and its scope.