The same openssl command verifies count.json and
log_count.txt — just swap the filenames.
Self-reported by the server at render time. Manifest and count
signatures are always verified in PHP via libsodium against the
published Ed25519 pubkey before display; the status feed
signature is verified when present. A FAILED result means the
payload or signature is missing, corrupted, or was not produced
by the key holder. Panel re-evaluates on each 60s refresh.