TUF security

Software delivery secured with TUF

TLS protects a connection. TUF protects the update decision even when a repository, registry, CDN or network path is untrusted. Devices verify signed metadata, target hashes, lengths, versions and expiry before accepting bytes.

Good fit

When to evaluate it

  • +Products where a compromised distribution service must not authorize arbitrary updates
  • +Teams that need offline root-key ceremonies
  • +Air-gapped and intermittently connected devices

Product boundary

What the current product does

A1

Pinned root

Enrollment gives each device the tenant trust root it will use to validate future metadata rotation.

A2

Separated roles

Offline root authority and scoped online publishing roles reduce the effect of one key or service compromise.

A3

Freshness and rollback checks

Versioned and expiring metadata lets the client reject older or indefinitely replayed repository state.

A4

Digest-verified targets

Transport is not trusted to choose or modify target bytes; signed metadata fixes their path, size and hash.

Explicit limit

TUF proves that authorized metadata selected exact bytes. It does not prove that those bytes are vulnerability-free, operationally healthy, or legally compliant, so Meshanics applies separate admission, health and evidence controls.

Questions

Does Meshanics require changes to application code?

No. The static Linux agent installs on the device and activates signed payloads through typed adapters. Health behavior and recovery limits are configured for the artifact, not embedded in customer application code.

Does Meshanics certify CRA compliance?

No. Meshanics records and exports evidence for the manufacturer's compliance work. The manufacturer remains responsible for product scope, risk decisions, conformity assessment, reporting, and declarations.