namespace EntitlementBLL.Options; /// /// ECDSA P-256 signing key configuration for the Entitlement bundle service, bound from /// appsettings "Entitlement:EcdsaKey". The private key is base64-encoded PKCS#8; never commit a /// real production key here — local dev should use a clearly-fake placeholder or generate one /// on first run (see EntitlementBundleService's dev-key fallback). /// public class EcdsaKeyOptions { public const string SectionName = "Entitlement:EcdsaKey"; /// Key identifier written into every signed bundle's KEYID / "kid" — supports rotation. public string KeyId { get; set; } = "dev-key-1"; /// Base64 PKCS#8 private key (ECDSA P-256). DEV-ONLY placeholder when unset — /// EntitlementBundleService generates an ephemeral in-memory key pair if this is empty, /// clearly logged as unsuitable for production. public string? PrivateKeyBase64 { get; set; } /// Base64 X.509 SubjectPublicKeyInfo public key (ECDSA P-256), used for verification /// when the signing key was generated out-of-process. Optional — if unset, verification uses /// the same in-memory key pair as signing (single-process dev scenario only). public string? PublicKeyBase64 { get; set; } }