Signing security policies

Before integrating a security policy into an installation package, you must sign the policy to guarantee its authenticity and integrity. You then become the policy signatory.

Stormshield provides a utility that allows you to sign your policies.

The signature is based on the JWT standard. The algorithm used by default is PS256, but you can configure it.

The signature utility makes it possible to sign several policies at the same time if needed.

When the policy signatory is changed, refer to the section Modifying the signatory of a security policy.