Nothing to try yet
No documentation found
Managed-settings and policy-limits caches are signature-checked against embedded trust roots, but only report telemetry for now.
A new signature-verification path checks managed-settings and policy-limits caches against embedded trust roots, using JWS with an x5c certificate chain and ES256. It computes age, cert-expiry, and chain-validation results, but currently only emits telemetry (tengu_signed_cache_shadow) rather than enforcing anything, as a shadow rollout of cache integrity checking.