ceterion Packaging Framework 2606: Package Sealing, Automatic Integrity Check, and Complete Trust Chain

The ceterion Packaging Framework 2606 is now available—with the introduction of Package Sealing, a new cryptographic integrity layer for enterprise packages. Together with Package Signing, which was introduced in 2022, this creates a complete trust chain: Signing verifies who built the package—Sealing verifies what is contained within it.

Verifiable. Enforceable. Automatic.

Highlights

Package Sealing — Integrity Built Into the Package

Starting with version 2606, the cmdlet New-PackageSeal introduced. It generates a complete integrity seal over the packet payload and embeds it directly into the package script – without a separate manifest file, without an external hash file.

  • Cmdlet: New-PackageSeal -Path <PackageFolder>
  • Hashing the entire package contents (files and folders)
  • Per-file MD5 hashes plus aggregated ManifestHash at the top level
  • The seal block is stored directly in the package script
  • Order: seal first, then sign (sealing removes existing Authenticode signatures)

Automatic integrity check during installation

Test-PackageSeal validates the package during installation – without the need for an operator to intervene. If the check fails, the deployment is aborted before any changes are made to the endpoint.

  • Cmdlet: Test-PackageSeal -Path <PackageFolder>
  • Automatic Invocation in the Installation Workflow
  • Throws an error for every validation issue
  • Modified, added, or missing files will stop the installation before it is deployed to the endpoint

Seal Schema v2 — Tamper Detection at the File and Manifest Levels

The new scheme detects any form of tampering with the package—including files added after sealing. This covers not only the modification of existing files but also the smuggling of additional payloads into an already sealed package.

  • Validation per file: existence, hash, length
  • Aggregated ManifestHash about the entire contents of the package
  • Detection of files added after sealing
  • Complete consistency check in a single step

The Complete Trust Chain: Sealing + Signing

New-PackageSeal complements the one that has been available since November 2022 Start-SignPackageScript into a closed trust chain. Both cmdlets address different trust issues and, when combined, ensure complete verifiability from construction through delivery.

  • Start-SignPackageScript (since Nov 2022) – Authenticode signature confirms the Origin (“Who built it?”)
  • New-PackageSeal (New in 2606) – The integrity seal confirms the Contents ("What's inside?")
  • Recommended Workflow: Seal → Sign → Ship
  • Both tests run automatically during the build and installation process

Further improvements

  • Complete module review of the sealing subsystem completed – the manifest, parser, and import were validated separately
  • Improved protection against tampered packet scripts through the central aggregate hash
  • Consistent cmdlet conventions throughout the *-PackageSeal-Family (New-PackageSeal, Test-PackageSeal)

With version 2606, package integrity is no longer a matter of process discipline—but a property that can be verified by the package itself: verifiable, enforceable, and automatic.