Bağımsız doğrulamaIndependent verification

Denetim kaydını kendiniz doğrulayınVerify the audit record yourself

Kurum kanıtı teslim eder, doğrulamayı denetçi yapar. Bunun için ürüne, sunucuya ya da bizim yazdığımız bir programa ihtiyaç yoktur. Windows ile gelen araçlar ya da openssl yeter. The organisation delivers the evidence, the auditor performs the verification. That needs no access to the product, no server and no software written by us. The tools that ship with Windows, or openssl, are enough.

Üç teslimThree deliveries

Farklı sorular, aynı ambalajDifferent questions, the same wrapper

Üç ayrı paket üretilir çünkü üç ayrı soruya cevap verirler ve farklı zamanlarda teslim edilirler. Ambalajları aynıdır: denetçi tek bir yordam öğrenir.Three separate packages exist because they answer three separate questions and are delivered at different times. Their wrapper is identical, so the auditor learns one procedure.

PaketPackage Hangi soruyu cevaplarThe question it answers İçindeki veri dosyasıIts data file
Denetim dosyasıEvidence dossier
SQLChangeGuard-Evidence
Örneklediğiniz tek bir talebin baştan sona hikâyesi. Kim istedi, hangi kurala göre onaylandı, kim çalıştırdı, betik o gün ne idi.The end to end story of the single request you sampled. Who asked for it, under which rule it was approved, who ran it, what the script was that day. Dossier.json
Dossier.pdf
Çapa paketiAnchor package
SQLChangeGuard-Anchors
Bir tarih aralığındaki günlük çapalar. Her çapa, alındığı andaki son kaydın özetini imzalı olarak taşır. Düzenli olarak, denetimden önce teslim edilir.The daily anchors for a date range. Each anchor carries, under signature, the digest of the last record at the moment it was taken. It is delivered regularly, ahead of the audit. Anchors.json
Kayıt paketiAudit records package
SQLChangeGuard-AuditRecords
Seçtiğiniz kayıt numarası aralığındaki ham denetim satırları. Çapadaki iddianın bugünkü kayıtla karşılaştırılabildiği tek teslim budur.The raw audit rows for the record number range you choose. This is the only delivery that lets the claim inside an anchor be compared against today's records. Package.json

Neden tek dosya değil. Çapa, denetimden önce teslim edilmiş olmalıdır; değeri erken teslim edilmiş olmasından gelir. Kayıtlarla aynı anda gelen bir çapa, kayıtları yazan tarafın aynı anda ürettiği iki dosyadır ve hiçbir şey kanıtlamaz. Üç paketi tek dosyada birleştirmek, çapanın tek kanıt değerini yok ederdi. Why not a single file. The anchor has to have been delivered before the audit; its value comes from being early. An anchor that arrives together with the records is just two files produced at the same moment by the same party, and proves nothing. Merging all three into one file would destroy the only evidential value the anchor has.

Paketin içiInside the package

Her zip aynı beş şeyi taşırEvery zip carries the same five things

DosyaFile Ne işe yararWhat it is for
Veri dosyasıThe data file Dossier.json, Anchors.json ya da Package.json. Kanıtın kendisi. Düz metin JSON, gözle de okunur.Dossier.json, Anchors.json or Package.json. The evidence itself. Plain text JSON, readable by eye.
Manifest.json Paketin künyesi: kurulum kimliği, ürün sürümü, aralık ve paketteki her dosyanın SHA-256 özeti. Paketten bir dosya çıkarıldığında bunu yakalayan şey listenin kendisidir.The package identity block: installation id, product version, range, and the SHA-256 digest of every file in the package. Removing a file from the package is caught by this list.
Manifest.sig Manifest.json baytlarının RSA imzası. Base64. İmza teslim edilen baytların üzerindedir, yeniden hesaplanmış bir kopyanın değil.The RSA signature over the bytes of Manifest.json, in Base64. The signature is over the bytes that were delivered, not over a recomputed copy.
PublicKey.pem Manifesti imzalayan anahtarın açık kısmı. Çapa paketi bir anahtar değişimini kapsıyorsa eski anahtarlar ayrıca PublicKey-<kimlik>.pem olarak konur, çünkü tek dosyada birleştirilmiş bir PEM'den openssl yalnız ilk anahtarı okur.The public half of the key that signed the manifest. When an anchor package spans a key change, the older keys ship separately as PublicKey-<id>.pem, because openssl reads only the first key out of a concatenated PEM file.
Verify.ps1 Yukarıdaki kontrolleri sizin yerinize çalıştıran betik. Betiğin özeti de manifeste yazılıdır, yani değiştirilmiş bir sürüm yakalanır. Kolaylıktır, kanıt değildir.A script that runs the checks above for you. Its own digest is listed in the manifest, so a modified copy is caught. It is a convenience, not the evidence.

İmza parametreleri sabittir ve kanıt biçim şartnamesinde yazılıdır: RSA (asgari 3072 bit), SHA-256, PKCS#1 v1.5, PEM anahtar, Base64 imza. Zaman damgası açıkken denetim dosyasına ayrıca Manifest.tsr eklenir; çapaların damgası ise çapa zarfının kendi içinde taşınır. The signature parameters are fixed and stated in the evidence format specification: RSA (3072 bit minimum), SHA-256, PKCS#1 v1.5, PEM key, Base64 signature. When timestamping is on, the evidence dossier also carries Manifest.tsr; the stamp on an anchor travels inside the anchor envelope itself.

DoğrulamaVerification

Dört adım, dört ayrı soruFour steps, four separate questions

Adımlar birbirinin yerine geçmez. Birinin geçmesi diğerini geçmiş saymaz.The steps do not substitute for each other. One passing does not make another pass.

1. Dosyalar değişmiş mi1. Have the files changed

Manifest.json içindeki listeye bakılır ve her dosyanın SHA-256 özeti yeniden hesaplanır. Tutmayan bir satır, o dosyanın paket üretildikten sonra değiştiğini gösterir.You read the list in Manifest.json and recompute the SHA-256 digest of every file. A row that does not match means that file changed after the package was produced.

Cevapladığı soru:The question it answers: elimdeki dosya, paketten çıktığı hâlde mi?is the file in front of me the one that came out of the package?

2. Manifest kimden geldi2. Who did the manifest come from

Manifest.sig, PublicKey.pem ile doğrulanır. Geçerse manifest, ilgili özel anahtarı elinde tutan kurulumdan çıkmıştır ve o günden beri tek bayt değişmemiştir.Manifest.sig is checked against PublicKey.pem. If it passes, the manifest came from the installation that holds the matching private key and has not changed by a single byte since.

Cevapladığı soru:The question it answers: bu liste gerçekten kurumun kendi anahtarıyla mı mühürlendi?was this list really sealed with the organisation's own key?

3. Anahtar doğru anahtar mı3. Is the key the right key

Açık anahtarın parmak izi hesaplanır ve kurumun bu paketin dışında yayımladığı değerle karşılaştırılır. Bu adım atlanırsa 2. adım hiçbir şey kanıtlamaz: paketin içine kendi anahtarını koyan biri de imzayı geçirir.You compute the fingerprint of the public key and compare it with the value the organisation published outside this package. Skip this step and step 2 proves nothing: anyone who ships a package with a key of their own also passes the signature check.

Cevapladığı soru:The question it answers: paketi mühürleyen anahtar, kurumun ilan ettiği anahtar mı?is the key that sealed this package the key the organisation declared?

4. Kayıtlar sonradan değişmiş mi4. Have the records changed since

İlk üç adım ambalajı doğrular. Dördüncüsü kayıtların kendisine bakar ve anahtar gerektirmez: zincir bağlantısı, çapa karşılaştırması ve içeriğin yeniden hesaplanması. Üçü aşağıda ayrı ayrı anlatılıyor.The first three steps check the wrapper. The fourth looks at the records themselves and needs no key: chain linkage, the anchor comparison, and recomputing the content. All three are set out below.

Cevapladığı soru:The question it answers: kayıtlar sonradan yeniden yazılmış olabilir mi?could the records have been rewritten after the fact?

Anahtarsız üç kontrolThree checks that need no key

Denetçinin kurumdan hiçbir şey istemeden yapabildikleriWhat the auditor can do without asking the organisation for anything

Denetim zincirinin imza anahtarı kurumun içinde kalır ve dışarı çıkmaz. Bu üç kontrol o anahtarı gerektirmediği için denetçi tek başına yapabilir.The signing key of the audit chain stays inside the organisation and never leaves it. None of these three checks needs that key, so the auditor can run them alone.

Kontrol A: zincir bağlantısıCheck A: chain linkage

Kayıt paketindeki her satır, bir önceki satırın özetini taşır. Sıralı iki satır alınır ve öndekinin previousHash değeri, arkadakinin hash değerine eşit mi diye bakılır. Bu, kayıt paketinin içindeki satırlarla, tamamen elle yapılabilir.

Every row in the records package carries the digest of the row before it. You take two consecutive rows and check whether the previousHash of the later one equals the hash of the earlier one. This can be done entirely by hand, with nothing but the rows in the package.

Bu kontrolün sınırını bilmek önemlidir. Yalnızca özet değerlerini karşılaştırır; o özetin gerçekten yanındaki içeriğe ait olup olmadığını hesaplamaz, çünkü bunun için gizli anahtar gerekir. Dolayısıyla araya kayıt sıkıştırmayı ve satır silmeyi yakalar, ama içerik düzenlemesini tek başına yakalayamaz.

Knowing the limit of this check matters. It compares digest values only; it does not compute whether a digest really belongs to the content beside it, because that needs the secret key. So it catches an inserted row and a deleted row, but on its own it cannot catch a content edit.

Kontrol B: çapa karşılaştırmasıCheck B: the anchor comparison

Elinizde geçen aya ait, o zaman teslim alınmış bir çapa paketi var. İçindeki bir çapa şunu söylüyor: "o gün son kaydım 41.207 numaralıydı ve özeti şudur." Bu cümle imzalıdır ve o gün teslim edilmiştir.

You hold an anchor package from last month, received at the time. One anchor in it says: "on that day my last record was number 41,207 and its digest is this." That sentence is signed and it was delivered on that day.

Bugün kurumdan 41.207 numaralı kaydı içeren bir kayıt paketi istersiniz ve o satırın hash değerini çapadaki değerle karşılaştırırsınız. Tutuyorsa o kayıt, çapanın teslim edildiği günden beri değişmemiştir.

Today you ask for a records package covering record 41,207 and compare the hash of that row against the value in the anchor. If they match, that record has not changed since the day the anchor was delivered.

Bu kontrolün gücü tamamen çapanın size daha önce teslim edilmiş olmasına bağlıdır. Kayıtlarla aynı gün gelen bir çapa hiçbir şey kanıtlamaz; iki dosya da aynı anda üretilmiştir. Bu yüzden çapa teslimi denetim zamanına bırakılmaz, düzenli olarak yapılır. Her dışa aktarma da bir denetim olayıdır ve kaydedilir; kurumun düzenli teslim yaptığı sonradan bu kayıtlardan gösterilir. Aralık verilmezse paket kendiliğinden bir önceki teslimin bittiği yerden başlar, böylece iki teslim arasında boşluk kalmaz.

The strength of this check rests entirely on the anchor having been delivered to you earlier. An anchor that arrives on the same day as the records proves nothing; both files were produced at the same moment. That is why anchor delivery is not left until audit time but happens on a schedule. Each export is itself an audit event and is recorded, so a regular delivery habit can be shown from those records afterwards. If no range is given, the package starts where the previous delivery ended, leaving no gap between two deliveries.

Kontrol C: içeriğin yeniden hesaplanmasıCheck C: recomputing the content

Yukarıdaki iki kontrolün ortak boşluğu şudur: ikisi de yalnız özet değerlerine bakar. Bir kaydın içeriğini değiştirip özet alanına hiç dokunmayan biri her ikisini de geçerdi. Bağ tutar, çapa tutar, hiçbir şey görünmez.

The two checks above share one gap: both look only at digest values. Someone who changes the content of a record and leaves its digest field untouched would pass both. The link holds, the anchor holds, nothing shows.

Bu yüzden kayıtlar ikinci bir zincir taşır ve o zincir anahtarsızdır. Denetçi bu değeri kaydın içeriğinden kendi makinesinde yeniden hesaplar ve satırda yazan değerle karşılaştırır. Tutmuyorsa o kaydın içeriği değişmiştir.

So the records carry a second chain, and that one is keyless. The auditor recomputes the value from the content of the record on their own machine and compares it with what the row says. A mismatch means that record's content changed.

"Anahtarsızsa saldırgan da hesaplayabilir" itirazı doğrudur ve önemli değildir. Bu zincirin gücü gizlilikten gelmez; uç değerinin daha önce size teslim edilmiş çapada bulunmasından gelir. Saldırgan zinciri yeniden hesaplayabilir ama sizin çekmecenizdeki eski değeri değiştiremez. Git commit özetleri ve sertifika şeffaflık günlükleri aynı mantıkla çalışır.

The objection that a keyless value can be computed by an attacker too is correct and beside the point. This chain draws its strength not from secrecy but from its end value sitting in an anchor already delivered to you. An attacker can recompute the chain but cannot change the old value in your drawer. Git commit digests and certificate transparency logs work the same way.

Hesabın birebir tanımı kanıt biçim şartnamesindedir ve bir test vektörüyle birlikte verilir: belli bir girdi için beklenen çıktı yazılıdır, böylece kendi doğrulayıcınızı yazıp doğru çalıştığını sınayabilirsiniz.

The exact definition of the calculation is in the evidence format specification, together with a test vector: a given input with its expected output, so you can write your own verifier and check that it works.

Ürün bu karşılaştırmayı sizi beklemeden kendisi de yapar. Denetim bütünlük işi, geçmişte imzalanmış çapaları günlük olarak bugünkü kayıtlarla karşılaştırır ve sonucu çapa paketinin manifestine yazar. Manifest imzalı olduğu için bir bulguyu gizlemek imzayı düşürür. The product runs this comparison itself rather than waiting for you. The audit integrity job compares previously signed anchors against the current records every day, and writes the result into the manifest of the anchor package. Because the manifest is signed, hiding a finding breaks the signature.
KomutlarCommands

Kendi makinenizde çalıştırınRun it on your own machine

Zip dosyasını açın ve klasörün içinde çalıştırın. Ürüne bağlanmaz, ağa çıkmaz.Unzip the package and run these inside the folder. Nothing connects to the product and nothing goes over the network.

Windows, PowerShell ileOn Windows, with PowerShell

# Dosya ozetleri ve imza. Paketin icindeki betik ikisini de yapar.File digests and the signature. The script inside the package does both. powershell -ExecutionPolicy Bypass -File .\Verify.ps1 # Tek bir dosyanin ozetini elle almak icin:To compute the digest of a single file by hand: (Get-FileHash Anchors.json -Algorithm SHA256).Hash.ToLower()

Herhangi bir sistemde, openssl ileOn any system, with openssl

# Manifest imzasiThe manifest signature openssl dgst -sha256 -verify PublicKey.pem -signature Manifest.sig Manifest.json # Acik anahtar parmak izi (SPKI DER uzerinden SHA-256).The public key fingerprint (SHA-256 over the SPKI DER bytes). # PowerShell'de openssl ciktisini openssl'e BORU ILE vermeyin: boru orada birDo NOT pipe openssl into openssl in PowerShell. The pipe is a text stream # metin akisidir, ikili DER verisini bozar ve hata vermeden YANLIS deger uretir.there, it corrupts the binary DER and yields a WRONG value with no error. openssl pkey -pubin -in PublicKey.pem -outform DER -out pub.der openssl dgst -sha256 pub.der

Betik kanıtın parçası değildir. Verify.ps1 doğruladığı paketin içinden çıkar. Bağımsızlık isteyen denetçi, komutları en az bir kez kendi eliyle çalıştırmalıdır. Bağlayıcı tarif betikte değil, kanıt biçim şartnamesindedir; şartname talep üzerine verilir ve teslim edilen paketler ona göre üretilir. The script is not part of the evidence. Verify.ps1 ships inside the package it checks. An auditor who wants independence should run the commands by hand at least once. The authoritative procedure is not in the script but in the evidence format specification, which is available on request and which the delivered packages follow.

Denetçi içinFor the auditor

Kurumdan tam olarak ne isteyeceksinizExactly what to request from the organisation

Bu dört kalem istendiğinde doğrulamanın tamamı yapılabilir. Sırası önemlidir.With these four items in hand the whole verification can be done. The order matters.

  1. Açık anahtarın parmak izi. Paketlerden bağımsız, yazılı olarak. Bir kez istenir ve anahtar değişene kadar geçerlidir. Bu olmadan imza kontrolü kendi kendini onaylayan bir işleme düşer.The fingerprint of the public key, in writing and independent of any package. Requested once, valid until the key changes. Without it the signature check collapses into a self certifying exercise.
  2. Çapa paketi, düzenli olarak ve denetimden önce. Aylık ya da çeyreklik. Denetim günü istenen bir çapa kanıt değeri taşımaz; değeri erken teslim edilmiş olmasından gelir.The anchor package, on a schedule and ahead of the audit. Monthly or quarterly. An anchor requested on audit day carries no evidential weight; its value comes from having been delivered early.
  3. Örneklediğiniz taleplerin denetim dosyaları. Talep numaralarını siz verin. Kurumun sizin için seçmesi, kanıtı seçki hâline getirir.The evidence dossiers for the requests you sampled. Give the request numbers yourself. Letting the organisation choose turns the evidence into a selection.
  4. Kayıt paketi, elinizdeki çapanın kapsadığı numara aralığı için. Aralığı çapadan okuyup istersiniz. Kontrol B ve C'yi yapabildiğiniz tek teslim budur. Aralığı bir kayıt geriden başlatın: paketteki ilk satırın da doğrulanabilmesi için bir öncekinin değeri gerekir.The records package, for the number range covered by the anchor you hold. You read the range off the anchor and ask for it. This is the only delivery that lets you run Checks B and C. Start the range one record earlier: verifying the first row in the package needs the value of the one before it.

Beşinci bir kalem isteyebilirsiniz: kanıt biçim şartnamesi. Doğrulamanın bağlayıcı tarifi paketin içindeki betikte değil, o belgededir; talep üzerine verilir ve teslim edilen paketler ona göre üretilir. You can ask for a fifth item: the evidence format specification. The authoritative description of the verification is in that document rather than in the script inside the package; it is available on request and the delivered packages follow it.

Dürüst sınırThe honest boundary

Bu doğrulama neyi kanıtlar, neyi kanıtlamazWhat this verification proves, and what it does not

KanıtlarIt proves

  • Paket üretildiğinden beri değişmemiştir.The package has not changed since it was produced.
  • Paket, ilan edilmiş anahtarı elinde tutan kurulumdan çıkmıştır.It came from the installation holding the declared key.
  • Kayıtlar, size daha önce teslim edilmiş çapanın tarihinden beri değişmemiştir.The records have not changed since the date of the anchor you already held.
  • Araya kayıt sıkıştırılmamıştır.No record was inserted in the middle.
  • Kayıtların içeriği değişmemiştir. Bunu siz hesaplarsınız, kuruma sormazsınız.The content of the records has not changed. You compute this yourself rather than asking the organisation.

KanıtlamazIt does not prove

  • Kayda yazılanın o gün doğru olduğunu. Mühür, yazılanın erken yazıldığını gösterir; doğru olduğunu değil.That what was written was true that day. A seal shows the entry is early, not that it is correct.
  • Hiç kayıt üretilmemiş bir işlemin varlığını. Ürünün dışından yapılan bir müdahaleyi veritabanı seviyesindeki iz gösterir, mühür değil.The existence of an action that produced no record at all. An intervention made outside the product is surfaced by the database level trail, not by the seal.
  • Hiç teslim edilmemiş bir çapanın silinmediğini. Mühürlü kopya kapalıysa silinme yalnız eski teslimlerle görülür; paket bunu gizlemez, manifeste yazar.That an anchor never delivered was not deleted. With the sealed copy switched off, deletion is only visible against earlier deliveries; the package does not hide this, it states it in the manifest.

Bu ayrım sektörde tamper evident ile tamper proof arasındaki farktır. Değiştirilemez bir kayıt vaat etmiyoruz; değiştirildiğinde görünen bir kayıt üretiyoruz. İkincisi doğrulanabilir, birincisi yalnızca iddia edilebilir. This is the difference between tamper evident and tamper proof. We do not promise a record that cannot be altered; we produce one where alteration shows. The second can be verified, the first can only be asserted.

Zaman damgasıTimestamping

Tarihi üçüncü taraf söylesinLetting a third party state the date

İmza, paketin kimden çıktığını gösterir; ne zaman çıktığını değil. Tarihi kurum kendi sunucusunun saatinden yazar ve o saat değiştirilebilir.

A signature shows where a package came from, not when. The date is written from the organisation's own server clock, and that clock can be changed.

Bunu kapatmak için RFC 3161 zaman damgası desteklenir. Açıldığında paketin özeti dış bir zaman damgası sunucusuna gönderilir ve dönen yanıt Manifest.tsr olarak pakete konur. Böylece tarihi kurum değil, üçüncü bir taraf söyler.

RFC 3161 timestamping closes that gap. When it is switched on, the digest of the package is sent to an external timestamp authority and the response is placed in the package as Manifest.tsr. The date is then stated by a third party rather than by the organisation.

Dışarıya çıkan tek şey özettir. Kaydın kendisi hiçbir koşulda zaman damgası sunucusuna gitmez. Özellik tek bir ana anahtarla yönetilir; kapatıldığında hiçbir ağ çağrısı yapılmaz ve ürün internet olmadan çalışmaya devam eder.

The only thing that leaves the network is the digest. The record itself never goes to the timestamp authority under any circumstances. The feature is governed by a single master switch; when it is turned off no network call is made at all and the product keeps working without internet access.

Ürünle gelen ayar dosyasında özellik açık gelir ve ücretsiz, herkese açık bir otoriteye işaret eder; böylece kurulumun ilk gününde uçtan uca çalıştığı görülebilir. Üretimde bu adresin kurumun kendi anlaşmalı ya da kurum içi otoritesiyle değiştirilmesi gerekir: açık bir hizmet kurumsal taahhüt vermez ve kanıt zincirini dışarıya bağlar.

The configuration that ships with the product has the feature on and points at a free public authority, so an installation can be seen working end to end on day one. In production that address should be replaced with the organisation's own contracted or internal authority: a public service makes no commitment and ties the evidence chain to something outside the organisation.

Sunucuya ulaşılamazsa iş durmaz, paket damgasız üretilir ve eksiklik gizlenmez: dosya konmaz, çapa zarfındaki damga alanı boş kalır ve günlüğe uyarı yazılır. Denetçi o pakette tarihin kurumun kendi beyanı olduğunu görür.

If the authority cannot be reached the work does not stop, the package is produced without a stamp, and the gap is not hidden: the file is omitted, the stamp field in the anchor envelope stays empty and a warning is written to the log. On such a package the auditor can see that the date is the organisation's own assertion.

DevamıNext