Evidence for a specific decision
Does an expired signing certificate invalidate an artifact?
You are checking a signed artifact after its short-lived certificate has expired. The relevant question is whether trusted evidence establishes signing during the certificate’s validity, under the verifier’s policy. Expiry at review time alone does not answer that question.
The published answer
Sigstore’s bundle documentation explains how trusted signing-time evidence can support verification after a short-lived signing certificate expires. The verifier must establish signing within the certificate’s validity and apply its trust policy. A timestamp does not by itself establish artifact safety or the truth of signed content.
The Sigstore reference describes how a bundle can carry timing evidence for later verification. It is documentation review, not verification of your artifact. The timestamp’s trust and the verifier’s rules remain part of the decision, and authentic content can still be incorrect or unsafe.
What to check in your own case
- Identify the bundle, signing certificate and timing evidence being verified.
- Check the verifier’s trusted issuers and timing rules rather than treating any timestamp as sufficient.
- Evaluate artifact safety and the truth of signed claims separately from signature authenticity.
Sources and exclusions
Published evidence record · Reviewed 2026-10-07
- Not established: artifact safety.
- Not established: truth of signed statements.
- Not established: verification without trust-policy checks.
Save the evidence behind your review
A saved snapshot preserves the documented verification conditions used in your review. The paid INDEX receipt is unsigned and is not itself a Sigstore verification result.
The complete answer is free. A saved snapshot costs £5 plus applicable VAT; an unsigned Evidence Receipt costs £19 plus applicable VAT. Recurring retrieval is also available. Retain your private access key before paying.
Use this example in an agent or API integration
Connect to https://varexis.tech/mcp, call find_evidence_questions with the search below, then use the returned route ID with preview_evidence_answer. No key is needed for previews.
{
"query": "Does an expired signing certificate invalidate an artifact?"
}The equivalent REST preview is POST https://varexis.tech/api/index/preview with JSON:
{
"route_id": "agentic_reviewed_sigstore_signing_time_verification"
}Actual published-snapshot excerpt; the full response also includes each public source record and its limitations:
{
"route_id": "agentic_reviewed_sigstore_signing_time_verification",
"answer": "Sigstore’s bundle documentation explains how trusted signing-time evidence can support verification after a short-lived signing certificate expires. The verifier must establish signing within the certificate’s validity and apply its trust policy. A timestamp does not by itself establish artifact safety or the truth of signed content.",
"snapshot_sha256": "d27b72cdd1da93be9ea06d1243ab2e8d76aca306294b63f1dd9c273790323e38",
"sources": [
{
"record_id": "VXI-EXT-SIGSTORE-BUNDLE-02-v1",
"url": "https://varexis.tech/varexis-index/records/sigstore-signing-time-verification.json",
"content_sha256": "63a8b6b2766885173d12071adf444750aaa6ba725f4fb16a1896223e19246669"
}
]
}
