1 Answers
The hash is taken of the log file itself, then Cloudtrail itself is uses a region specific private key to sign the digest. You/we have access to the public key for the region to validate the digest. Source: https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-log-file-validation-intro.html