From 8ea61f1bd6b6ff772b5d00fce7526091db1b0449 Mon Sep 17 00:00:00 2001 From: henrymitchellhibbert-lab Date: Thu, 8 Oct 2026 15:44:58 +1100 Subject: [PATCH 1/2] Update CycloneDX SBOM/VEX signing specification Updated signing requirements and procedures for CycloneDX documents to specify JSON Signature Format (JSF) must be used instead of JWS. This matches the CycloneDX spec. --- .../sbom_vex_metadata_spec.md | 20 +++++++++++++------ 1 file changed, 14 insertions(+), 6 deletions(-) diff --git a/sbom_vex_metadata_spec/sbom_vex_metadata_spec.md b/sbom_vex_metadata_spec/sbom_vex_metadata_spec.md index f2331a1..7193e50 100644 --- a/sbom_vex_metadata_spec/sbom_vex_metadata_spec.md +++ b/sbom_vex_metadata_spec/sbom_vex_metadata_spec.md @@ -184,7 +184,7 @@ The following fields MUST be populated as specified within the chosen SBOM or VE - The `bom-ref` of the component with the hardware model information needs to be specified under `dependencies` as a dependency of the OS with: - `"ref": ""` - `"dependsOn": [ "" ]` -- **Signature:** The document must be signed using the options supported in the [CycloneDX specification](https://cyclonedx.org/docs/1.7/json/#signature). +- **Signature:** The document must be signed using [JSON Signature Format](https://cyberphone.github.io/doc/security/jsf.html) as per the [CycloneDX specification](https://cyclonedx.org/docs/1.7/json/#signature). **Example:** @@ -373,19 +373,27 @@ Given that certificate-based signatures are required and CSAF VEX files use JSON } ``` -# Sign Documents Using [JSON Web Signature (JWS)](https://datatracker.ietf.org/doc/html/rfc7515) +# Instructions for Signing Documents -## JWS Serialization Protocol +## Signing CycloneDX Documents with [JSON Signature Format (JSF)](https://cyberphone.github.io/doc/security/jsf.html) -The [JWS JSON Serialization format](https://tools.ietf.org/html/rfc7515#section-3.2) must be employed for all signed VEX/SBOM documentation. Furthermore, signed JWS files are required to use the **.json** file extension. +CycloneDX documents must be signed using JSF per the [CycloneDX specification](https://cyclonedx.org/docs/1.7/json/#signature) using the instructions in the [JSF specification](https://cyberphone.github.io/doc/security/jsf.html#Signature_Creation). -## Signing Procedures +Document publishers must make their Root CA certificate available to consumers through a designated secure channel. + +## Signing SPDX and CSAF Documents Using [JSON Web Signature (JWS)](https://datatracker.ietf.org/doc/html/rfc7515) + +### JWS Serialization Protocol + +The [JWS JSON Serialization format](https://tools.ietf.org/html/rfc7515#section-3.2) must be employed for all signed SPDX and CSAF documents. Signed JWS files are required to use the **.json** file extension. + +### Signing Procedures - The JWS `payload` consists of the complete original JSON metadata, formatted as a UTF-8 string and Base64URL encoded (without padding). - All digital signatures are required to be certificate-based. - To facilitate trust establishment, document publishers must make their Root CA certificate available to consumers through a designated secure channel. -## Cryptographic Recommendations +### Cryptographic Recommendations - It is recommended to utilize robust algorithms such as ES256 (ECDSA P-256 with SHA-256) or RS256 (RSA with SHA-256). From faefd26aae678f9a1752c0fa02ad3071001322cc Mon Sep 17 00:00:00 2001 From: henrymitchellhibbert-lab Date: Thu, 8 Oct 2026 15:46:28 +1100 Subject: [PATCH 2/2] Update section title for signing CycloneDX documents --- sbom_vex_metadata_spec/sbom_vex_metadata_spec.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/sbom_vex_metadata_spec/sbom_vex_metadata_spec.md b/sbom_vex_metadata_spec/sbom_vex_metadata_spec.md index 7193e50..45e4e58 100644 --- a/sbom_vex_metadata_spec/sbom_vex_metadata_spec.md +++ b/sbom_vex_metadata_spec/sbom_vex_metadata_spec.md @@ -375,7 +375,7 @@ Given that certificate-based signatures are required and CSAF VEX files use JSON # Instructions for Signing Documents -## Signing CycloneDX Documents with [JSON Signature Format (JSF)](https://cyberphone.github.io/doc/security/jsf.html) +## Signing CycloneDX Documents Using [JSON Signature Format (JSF)](https://cyberphone.github.io/doc/security/jsf.html) CycloneDX documents must be signed using JSF per the [CycloneDX specification](https://cyclonedx.org/docs/1.7/json/#signature) using the instructions in the [JSF specification](https://cyberphone.github.io/doc/security/jsf.html#Signature_Creation).