Help Center/ Image Management Service/ FAQs/ Image Creation/ How Can Imported Private Images Be Signed Automatically?
Updated on 2026-08-10 GMT+08:00

How Can Imported Private Images Be Signed Automatically?

Scenarios

To prevent tampering of images published from private environments to Huawei Cloud, IMS provides auto sign for private images. When you create an image from an imported image file, the created image file can be automatically signed. When you use an automatically signed image to create EVS disks (including system and data disks), the created EVS disks automatically verify the image integrity based on the signature and display the verification result.

Constraints

  • A signed image cannot be shared with other users.
  • Automatic image signing is supported only in the following scenarios:
    • Creating a system disk image using an external image file
    • Creating a data disk image using an external image file

    Auto sign is only available for certain regions. You can see on the console if it is available for a given region.

Procedure

  1. Creating a signature key

    1. Log in to the DEW console.
    2. On the Key Management Service page, click Create Key in the upper right corner.
    3. On the Create Key page, enter a key name, select a key algorithm, and set Usage to SIGN_VERIFY. Retain the default values for other parameters.

  2. Use the signature key to automatically sign the image.

    1. Create a private image from an imported image file, select Auto sign in the Image Information area.

    2. Select the corresponding signature key.

    3. Complete the other settings to create a private image. On the image details page, view the digital signature, key ID, and key name.

  3. View the image integrity check result.

    1. After you use the signed image to create an EVS disk, click the target disk on the EVS list page to go to the details page and view the image integrity check result.

    2. If the image is tampered with, the image integrity check result is Failed.