Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“Digital Signature is not getting verified”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
1e154f0281a6a069d30e821013461790295033cce012d72909d6c95c703adbf4
Signature (Ed25519, base64)
6uvCxiwFboeKP1/ASXCmKHCvzOUzJveX/gBe4SmQl9RrhCCDQrTRAxuiNrep06O37C6iA5c5YUtwADcIngyxDw==
Merkle root
feb82b7f8aea18b46b248fac49fdc21a6b138fec64dc2fa12c4b3c7a81799706
Merkle path
["1e14750d7ec9a5008528a5ea64979aa7de32af269208a984bb007039dd855f61","0efe5d4c60d314d9048f0a61c28d67ec6003727aeb05d10770178b9e1c077d58","4317da18a41315af76b31a640c51c0924fe1d780caf2d02ba1e793926faa313f","ce1ee26e3649d6dfc30c8676cf00f2c39ebfd305c701004645ecda8067fc2542","673e2c4db02e4790e9437b358b0dd131b3df15654e348f94b9fdf9ab1175c0a8","8ec48e20f0d656a4a220bd5193b7cf3803d87df0c2e2cc3fd8e1a4f381f30b53","eaf1d0b6e617ea06a2d79596152ed7bfbdc1d9d4383668bbc21ae43e8188f44e","1674cb10e431bb6af3b7180ae8ea4dd50085523d7226728f155f956cefa01ddc","f6bd2f084904e755e5a1f63ef8638ba51e9cef76bd5821cbce0f61d6fa729e5a","3fd3846d0131fe45f7d07ecbd8d56884303418046dca55a756d9969d4df82541","cf77f2a706b7ca35e10a87b8133f6c65d58e187ce763515460edf9a6388a03c8","a86586d097ad6dfcc4efd60a975e3fb89148c9a3be61ec9b351b9cc4a0526bb6","ce9fe8fedce3454cf180d6a66efdbe5fbdc70a0fa838f69d2b9096cbcc6c4c38","e77d494af9e2547c53e58f62769cd14d89c9d23aad38b861f53f29b79396acd3","3520002e20f205a5e2c7683df52b5c77fe454ada68a85506f659d94f96d1078c"]
Anchored
2026-10-07
Public log entry
search.sigstore.dev, log index 3122521988 · entry 108e9186e8c5677afa72…
Expected log hash
9fa0d177312c5b0b22ba9dc313f3316134d71d179dc19912df4abe4610de68bf The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1791343163559","kind":"published-quote","locale":"en","page":"brand:foxit","quote":"Digital Signature is not getting verified","rating":2,"review_date":"2026-10-04","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=com.foxit.mobile.pdf.lite","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (feb82b7f8aea…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.