Kurum kanıtı teslim eder, doğrulamayı denetçi yapar. Bunun için ürüne, sunucuya ya da bizim yazdığımız bir programa ihtiyaç yoktur. Windows ile gelen araçlar ya da openssl yeter. The organisation delivers the evidence, the auditor performs the verification. That needs no access to the product, no server and no software written by us. The tools that ship with Windows, or openssl, are enough.
Üç ayrı paket üretilir çünkü üç ayrı soruya cevap verirler ve farklı zamanlarda teslim edilirler. Ambalajları aynıdır: denetçi tek bir yordam öğrenir.Three separate packages exist because they answer three separate questions and are delivered at different times. Their wrapper is identical, so the auditor learns one procedure.
| PaketPackage | Hangi soruyu cevaplarThe question it answers | İçindeki veri dosyasıIts data file |
|---|---|---|
| Denetim dosyasıEvidence dossier SQLChangeGuard-Evidence |
Örneklediğiniz tek bir talebin baştan sona hikâyesi. Kim istedi, hangi kurala göre onaylandı, kim çalıştırdı, betik o gün ne idi.The end to end story of the single request you sampled. Who asked for it, under which rule it was approved, who ran it, what the script was that day. | Dossier.json Dossier.pdf |
| Çapa paketiAnchor package SQLChangeGuard-Anchors |
Bir tarih aralığındaki günlük çapalar. Her çapa, alındığı andaki son kaydın özetini imzalı olarak taşır. Düzenli olarak, denetimden önce teslim edilir.The daily anchors for a date range. Each anchor carries, under signature, the digest of the last record at the moment it was taken. It is delivered regularly, ahead of the audit. | Anchors.json |
| Kayıt paketiAudit records package SQLChangeGuard-AuditRecords |
Seçtiğiniz kayıt numarası aralığındaki ham denetim satırları. Çapadaki iddianın bugünkü kayıtla karşılaştırılabildiği tek teslim budur.The raw audit rows for the record number range you choose. This is the only delivery that lets the claim inside an anchor be compared against today's records. | Package.json |
Neden tek dosya değil. Çapa, denetimden önce teslim edilmiş olmalıdır; değeri erken teslim edilmiş olmasından gelir. Kayıtlarla aynı anda gelen bir çapa, kayıtları yazan tarafın aynı anda ürettiği iki dosyadır ve hiçbir şey kanıtlamaz. Üç paketi tek dosyada birleştirmek, çapanın tek kanıt değerini yok ederdi. Why not a single file. The anchor has to have been delivered before the audit; its value comes from being early. An anchor that arrives together with the records is just two files produced at the same moment by the same party, and proves nothing. Merging all three into one file would destroy the only evidential value the anchor has.
| DosyaFile | Ne işe yararWhat it is for |
|---|---|
| Veri dosyasıThe data file | Dossier.json, Anchors.json ya da Package.json. Kanıtın kendisi. Düz metin JSON, gözle de okunur.Dossier.json, Anchors.json or Package.json. The evidence itself. Plain text JSON, readable by eye. |
| Manifest.json | Paketin künyesi: kurulum kimliği, ürün sürümü, aralık ve paketteki her dosyanın SHA-256 özeti. Paketten bir dosya çıkarıldığında bunu yakalayan şey listenin kendisidir.The package identity block: installation id, product version, range, and the SHA-256 digest of every file in the package. Removing a file from the package is caught by this list. |
| Manifest.sig | Manifest.json baytlarının RSA imzası. Base64. İmza teslim edilen baytların üzerindedir, yeniden hesaplanmış bir kopyanın değil.The RSA signature over the bytes of Manifest.json, in Base64. The signature is over the bytes that were delivered, not over a recomputed copy. |
| PublicKey.pem | Manifesti imzalayan anahtarın açık kısmı. Çapa paketi bir anahtar değişimini kapsıyorsa eski anahtarlar ayrıca PublicKey-<kimlik>.pem olarak konur, çünkü tek dosyada birleştirilmiş bir PEM'den openssl yalnız ilk anahtarı okur.The public half of the key that signed the manifest. When an anchor package spans a key change, the older keys ship separately as PublicKey-<id>.pem, because openssl reads only the first key out of a concatenated PEM file. |
| Verify.ps1 | Yukarıdaki kontrolleri sizin yerinize çalıştıran betik. Betiğin özeti de manifeste yazılıdır, yani değiştirilmiş bir sürüm yakalanır. Kolaylıktır, kanıt değildir.A script that runs the checks above for you. Its own digest is listed in the manifest, so a modified copy is caught. It is a convenience, not the evidence. |
İmza parametreleri sabittir ve kanıt biçim şartnamesinde yazılıdır: RSA (asgari 3072 bit), SHA-256, PKCS#1 v1.5, PEM anahtar, Base64 imza. Zaman damgası açıkken denetim dosyasına ayrıca Manifest.tsr eklenir; çapaların damgası ise çapa zarfının kendi içinde taşınır. The signature parameters are fixed and stated in the evidence format specification: RSA (3072 bit minimum), SHA-256, PKCS#1 v1.5, PEM key, Base64 signature. When timestamping is on, the evidence dossier also carries Manifest.tsr; the stamp on an anchor travels inside the anchor envelope itself.
Adımlar birbirinin yerine geçmez. Birinin geçmesi diğerini geçmiş saymaz.The steps do not substitute for each other. One passing does not make another pass.
Manifest.json içindeki listeye bakılır ve her dosyanın SHA-256 özeti yeniden hesaplanır. Tutmayan bir satır, o dosyanın paket üretildikten sonra değiştiğini gösterir.You read the list in Manifest.json and recompute the SHA-256 digest of every file. A row that does not match means that file changed after the package was produced.
Cevapladığı soru:The question it answers: elimdeki dosya, paketten çıktığı hâlde mi?is the file in front of me the one that came out of the package?
Manifest.sig, PublicKey.pem ile doğrulanır. Geçerse manifest, ilgili özel anahtarı elinde tutan kurulumdan çıkmıştır ve o günden beri tek bayt değişmemiştir.Manifest.sig is checked against PublicKey.pem. If it passes, the manifest came from the installation that holds the matching private key and has not changed by a single byte since.
Cevapladığı soru:The question it answers: bu liste gerçekten kurumun kendi anahtarıyla mı mühürlendi?was this list really sealed with the organisation's own key?
Açık anahtarın parmak izi hesaplanır ve kurumun bu paketin dışında yayımladığı değerle karşılaştırılır. Bu adım atlanırsa 2. adım hiçbir şey kanıtlamaz: paketin içine kendi anahtarını koyan biri de imzayı geçirir.You compute the fingerprint of the public key and compare it with the value the organisation published outside this package. Skip this step and step 2 proves nothing: anyone who ships a package with a key of their own also passes the signature check.
Cevapladığı soru:The question it answers: paketi mühürleyen anahtar, kurumun ilan ettiği anahtar mı?is the key that sealed this package the key the organisation declared?
İlk üç adım ambalajı doğrular. Dördüncüsü kayıtların kendisine bakar ve anahtar gerektirmez: zincir bağlantısı, çapa karşılaştırması ve içeriğin yeniden hesaplanması. Üçü aşağıda ayrı ayrı anlatılıyor.The first three steps check the wrapper. The fourth looks at the records themselves and needs no key: chain linkage, the anchor comparison, and recomputing the content. All three are set out below.
Cevapladığı soru:The question it answers: kayıtlar sonradan yeniden yazılmış olabilir mi?could the records have been rewritten after the fact?
Denetim zincirinin imza anahtarı kurumun içinde kalır ve dışarı çıkmaz. Bu üç kontrol o anahtarı gerektirmediği için denetçi tek başına yapabilir.The signing key of the audit chain stays inside the organisation and never leaves it. None of these three checks needs that key, so the auditor can run them alone.
Kayıt paketindeki her satır, bir önceki satırın özetini taşır. Sıralı iki satır alınır ve öndekinin previousHash değeri, arkadakinin hash değerine eşit mi diye bakılır. Bu, kayıt paketinin içindeki satırlarla, tamamen elle yapılabilir.
Every row in the records package carries the digest of the row before it. You take two consecutive rows and check whether the previousHash of the later one equals the hash of the earlier one. This can be done entirely by hand, with nothing but the rows in the package.
Bu kontrolün sınırını bilmek önemlidir. Yalnızca özet değerlerini karşılaştırır; o özetin gerçekten yanındaki içeriğe ait olup olmadığını hesaplamaz, çünkü bunun için gizli anahtar gerekir. Dolayısıyla araya kayıt sıkıştırmayı ve satır silmeyi yakalar, ama içerik düzenlemesini tek başına yakalayamaz.
Knowing the limit of this check matters. It compares digest values only; it does not compute whether a digest really belongs to the content beside it, because that needs the secret key. So it catches an inserted row and a deleted row, but on its own it cannot catch a content edit.
Elinizde geçen aya ait, o zaman teslim alınmış bir çapa paketi var. İçindeki bir çapa şunu söylüyor: "o gün son kaydım 41.207 numaralıydı ve özeti şudur." Bu cümle imzalıdır ve o gün teslim edilmiştir.
You hold an anchor package from last month, received at the time. One anchor in it says: "on that day my last record was number 41,207 and its digest is this." That sentence is signed and it was delivered on that day.
Bugün kurumdan 41.207 numaralı kaydı içeren bir kayıt paketi istersiniz ve o satırın hash değerini çapadaki değerle karşılaştırırsınız. Tutuyorsa o kayıt, çapanın teslim edildiği günden beri değişmemiştir.
Today you ask for a records package covering record 41,207 and compare the hash of that row against the value in the anchor. If they match, that record has not changed since the day the anchor was delivered.
Bu kontrolün gücü tamamen çapanın size daha önce teslim edilmiş olmasına bağlıdır. Kayıtlarla aynı gün gelen bir çapa hiçbir şey kanıtlamaz; iki dosya da aynı anda üretilmiştir. Bu yüzden çapa teslimi denetim zamanına bırakılmaz, düzenli olarak yapılır. Her dışa aktarma da bir denetim olayıdır ve kaydedilir; kurumun düzenli teslim yaptığı sonradan bu kayıtlardan gösterilir. Aralık verilmezse paket kendiliğinden bir önceki teslimin bittiği yerden başlar, böylece iki teslim arasında boşluk kalmaz.
The strength of this check rests entirely on the anchor having been delivered to you earlier. An anchor that arrives on the same day as the records proves nothing; both files were produced at the same moment. That is why anchor delivery is not left until audit time but happens on a schedule. Each export is itself an audit event and is recorded, so a regular delivery habit can be shown from those records afterwards. If no range is given, the package starts where the previous delivery ended, leaving no gap between two deliveries.
Yukarıdaki iki kontrolün ortak boşluğu şudur: ikisi de yalnız özet değerlerine bakar. Bir kaydın içeriğini değiştirip özet alanına hiç dokunmayan biri her ikisini de geçerdi. Bağ tutar, çapa tutar, hiçbir şey görünmez.
The two checks above share one gap: both look only at digest values. Someone who changes the content of a record and leaves its digest field untouched would pass both. The link holds, the anchor holds, nothing shows.
Bu yüzden kayıtlar ikinci bir zincir taşır ve o zincir anahtarsızdır. Denetçi bu değeri kaydın içeriğinden kendi makinesinde yeniden hesaplar ve satırda yazan değerle karşılaştırır. Tutmuyorsa o kaydın içeriği değişmiştir.
So the records carry a second chain, and that one is keyless. The auditor recomputes the value from the content of the record on their own machine and compares it with what the row says. A mismatch means that record's content changed.
"Anahtarsızsa saldırgan da hesaplayabilir" itirazı doğrudur ve önemli değildir. Bu zincirin gücü gizlilikten gelmez; uç değerinin daha önce size teslim edilmiş çapada bulunmasından gelir. Saldırgan zinciri yeniden hesaplayabilir ama sizin çekmecenizdeki eski değeri değiştiremez. Git commit özetleri ve sertifika şeffaflık günlükleri aynı mantıkla çalışır.
The objection that a keyless value can be computed by an attacker too is correct and beside the point. This chain draws its strength not from secrecy but from its end value sitting in an anchor already delivered to you. An attacker can recompute the chain but cannot change the old value in your drawer. Git commit digests and certificate transparency logs work the same way.
Hesabın birebir tanımı kanıt biçim şartnamesindedir ve bir test vektörüyle birlikte verilir: belli bir girdi için beklenen çıktı yazılıdır, böylece kendi doğrulayıcınızı yazıp doğru çalıştığını sınayabilirsiniz.
The exact definition of the calculation is in the evidence format specification, together with a test vector: a given input with its expected output, so you can write your own verifier and check that it works.
Zip dosyasını açın ve klasörün içinde çalıştırın. Ürüne bağlanmaz, ağa çıkmaz.Unzip the package and run these inside the folder. Nothing connects to the product and nothing goes over the network.
Betik kanıtın parçası değildir. Verify.ps1 doğruladığı paketin içinden çıkar. Bağımsızlık isteyen denetçi, komutları en az bir kez kendi eliyle çalıştırmalıdır. Bağlayıcı tarif betikte değil, kanıt biçim şartnamesindedir; şartname talep üzerine verilir ve teslim edilen paketler ona göre üretilir. The script is not part of the evidence. Verify.ps1 ships inside the package it checks. An auditor who wants independence should run the commands by hand at least once. The authoritative procedure is not in the script but in the evidence format specification, which is available on request and which the delivered packages follow.
Bu dört kalem istendiğinde doğrulamanın tamamı yapılabilir. Sırası önemlidir.With these four items in hand the whole verification can be done. The order matters.
Beşinci bir kalem isteyebilirsiniz: kanıt biçim şartnamesi. Doğrulamanın bağlayıcı tarifi paketin içindeki betikte değil, o belgededir; talep üzerine verilir ve teslim edilen paketler ona göre üretilir. You can ask for a fifth item: the evidence format specification. The authoritative description of the verification is in that document rather than in the script inside the package; it is available on request and the delivered packages follow it.
Bu ayrım sektörde tamper evident ile tamper proof arasındaki farktır. Değiştirilemez bir kayıt vaat etmiyoruz; değiştirildiğinde görünen bir kayıt üretiyoruz. İkincisi doğrulanabilir, birincisi yalnızca iddia edilebilir. This is the difference between tamper evident and tamper proof. We do not promise a record that cannot be altered; we produce one where alteration shows. The second can be verified, the first can only be asserted.
İmza, paketin kimden çıktığını gösterir; ne zaman çıktığını değil. Tarihi kurum kendi sunucusunun saatinden yazar ve o saat değiştirilebilir.
A signature shows where a package came from, not when. The date is written from the organisation's own server clock, and that clock can be changed.
Bunu kapatmak için RFC 3161 zaman damgası desteklenir. Açıldığında paketin özeti dış bir zaman damgası sunucusuna gönderilir ve dönen yanıt Manifest.tsr olarak pakete konur. Böylece tarihi kurum değil, üçüncü bir taraf söyler.
RFC 3161 timestamping closes that gap. When it is switched on, the digest of the package is sent to an external timestamp authority and the response is placed in the package as Manifest.tsr. The date is then stated by a third party rather than by the organisation.
Dışarıya çıkan tek şey özettir. Kaydın kendisi hiçbir koşulda zaman damgası sunucusuna gitmez. Özellik tek bir ana anahtarla yönetilir; kapatıldığında hiçbir ağ çağrısı yapılmaz ve ürün internet olmadan çalışmaya devam eder.
The only thing that leaves the network is the digest. The record itself never goes to the timestamp authority under any circumstances. The feature is governed by a single master switch; when it is turned off no network call is made at all and the product keeps working without internet access.
Ürünle gelen ayar dosyasında özellik açık gelir ve ücretsiz, herkese açık bir otoriteye işaret eder; böylece kurulumun ilk gününde uçtan uca çalıştığı görülebilir. Üretimde bu adresin kurumun kendi anlaşmalı ya da kurum içi otoritesiyle değiştirilmesi gerekir: açık bir hizmet kurumsal taahhüt vermez ve kanıt zincirini dışarıya bağlar.
The configuration that ships with the product has the feature on and points at a free public authority, so an installation can be seen working end to end on day one. In production that address should be replaced with the organisation's own contracted or internal authority: a public service makes no commitment and ties the evidence chain to something outside the organisation.
Sunucuya ulaşılamazsa iş durmaz, paket damgasız üretilir ve eksiklik gizlenmez: dosya konmaz, çapa zarfındaki damga alanı boş kalır ve günlüğe uyarı yazılır. Denetçi o pakette tarihin kurumun kendi beyanı olduğunu görür.
If the authority cannot be reached the work does not stop, the package is produced without a stamp, and the gap is not hidden: the file is omitted, the stamp field in the anchor envelope stays empty and a warning is written to the log. On such a package the auditor can see that the date is the organisation's own assertion.