ADORSYS-GIS / ADORSYS-GIS/cloud-identity-wallet
Add VICAL-based trust store distribution for IACA roots
- 主要言語
- Rust
- スター
- 4
- フォーク
- 0
- PR マージ指標
- 30日以内にマージされた PR はありません
説明
The current `StaticTrustStore` requires operators to manually configure trusted IACA root certificates at startup. ISO/IEC 18013-5 Annex C (informative) describes the Verified Issuer Certificate Authority List (VICAL) — a standardised, signed list of trusted IACA roots that a verifier can fetch and refresh automatically.
This is operational infrastructure, not a cryptographic correctness gap. It becomes relevant when the wallet needs to trust issuers across jurisdictions without a code/config change per issuer.
**Scope**
- Add a `VicalTrustStore` implementing the existing `IacaTrustStore` trait
- Fetch and parse a VICAL document (signed CBOR/COSE structure)
- Verify the VICAL signature against a configured VICAL provider key
- Extract IACA root certificates from the VICAL entries
- Support periodic refresh
**Acceptance Criteria**
- [ ] `VicalTrustStore` implements `IacaTrustStore` and is drop-in compatible with `verify_issuer_signature`
- [ ] VICAL document signature verified before any root is trusted
- [ ] Roots extracted and exposed via `trusted_roots()`
- [ ] Configurable refresh interval
- [ ] Tests: valid VICAL parsed and roots extracted, tampered VICAL rejected
**Priority:** Low operational convenience; `StaticTrustStore` is sufficient for known-issuer deployments.
**Note:** Annex C is informative, not normative. This is an enhancement, not a compliance requirement.
**References**
- ISO/IEC 18013-5 Annex C — VICAL (informative)
コントリビューションガイド
評価
この issue はまだ評価されていません。