Integrity Mismatch
An integrity mismatch means that observed content does not satisfy the recorded integrity expectation.
- Confirm that the correct artifact is being verified.
- Compare artifact identifiers and versions.
- Recalculate the relevant integrity value.
- Check whether the file changed after evidence generation.
- Confirm that the evidence belongs to the current artifact.
Do not
Section titled “Do not”Do not replace the recorded integrity value merely to make verification succeed.
Resolution
Section titled “Resolution”If the content was intentionally changed, generate a new evidence record for the new artifact.
If the change was unintended, restore the expected artifact before continuing.