CAP never authorizes.
Strict verification boundary for already-framed protocol bytes.
Ed25519: before invoking OTP crypto, this module rejects noncanonical
point encodings, the complete eight-point torsion set for both the public
key and R, and scalars outside the canonical subgroup-order range. This
prevents low-order universal forgeries that the raw runtime primitive can
accept.
ML-DSA: lattice signatures carry no torsion or point-encoding surface; the strictness rule is the registry row's exact public-key and signature byte lengths for the named parameterization, enforced before OTP crypto. Verification is pure ML-DSA with the context fixed to the empty string (RFC 9964).
The module accepts only public verification material. It never signs, selects trust, or authorizes an artifact.
Summary
Functions
Verify one exact message and signature with a raw public key under the
registry's key algorithm for alg.
Functions
@spec verify(term(), term(), term(), term()) :: :ok | {:error, CharterAgreementProtocol.Error.t()}
Verify one exact message and signature with a raw public key under the
registry's key algorithm for alg.
The signature and public-key byte lengths must equal the registry row's exact values; anything else rejects before cryptographic work.