Section 83 of 101
82. Signed Configuration
Stable section ID: S05-CON-006-SECTION-83 · 35 content blocks
Every authoritative Configuration Baseline and safety-relevant configuration package shall be digitally signed or protected through an equivalent integrity and authorization mechanism.
A signed configuration shall identify:
Building ID;
Configuration Version ID;
configuration content or integrity value;
approving authority;
signing identity;
approval time;
effective time;
applicable BIOS versions;
applicable Engineering Profiles;
permitted hardware or deployment scope;
expiration or review condition;
relationship to the preceding configuration.
The BIOS shall verify before activation:
signature validity;
signer authority;
configuration integrity;
version sequence;
schema compatibility;
revocation status;
applicable building identity;
- required co-approvals.
- Any unauthorized modification shall invalidate the affected signature.
The BIOS shall distinguish among:
unsigned draft;
signed proposal;
approved inactive configuration;
active signed baseline;
superseded signed baseline;
revoked configuration;
emergency temporary configuration.
Emergency configuration may use an accelerated approval process but shall remain signed, time-limited, scoped, and subject to later review.
Configuration signatures shall not be transferred between buildings unless the package was explicitly designed as a reusable Type-level configuration and project-specific validation remains complete.
Loss of a signing key shall not require deletion of previously valid historical configurations. Trust records shall preserve when the signature was valid and whether later revocation affects historical or future use.