Skip to main content

Trust

Wallets and verifiers only accept EUDIPLO if they trust its certificates, and EUDIPLO only accepts credentials and wallets it can trust. This section covers both directions. Pick the page for your task:

I want to...Read
Create or import the keys that sign credentials, status lists, trust lists and requestsKeys and Certificates
Know which certificates a specific wallet needsWallet and Registrar Requirements
Get access and registration certificates from the German registrar, publish schema metadataRegistrar
Tell wallets what my verifier may request or which credentials my issuer providesRegistration Certificates
Accept credentials only from specific issuers, or publish a list of my own issuersTrust Lists
Decide trust through OpenID Federation trust anchorsOpenID Federation
Issue only to trusted wallet apps and to keys with a certain security levelWallet and Key Attestation

Who proves what to whom​

DirectionWhat is presentedChecked against
EUDIPLO as verifier → walletPresentation requests signed with the access certificate, optionally with a registration certificate that authorizes the requested dataThe wallet's trust in the access certificate's issuer and the registrar
EUDIPLO as issuer → walletCredentials signed with an attestation key chain; optionally signed issuer metadata (access certificate) and a registration certificate in issuer_infoTrust lists or the ecosystem's trust anchors, in the wallet
Wallet → EUDIPLO as verifierCredentials with the issuer's certificate chain, status lists signed by the issuer's revocation certificateTrust lists or federation in trusted_authorities
Wallet → EUDIPLO as issuerWallet attestation at the authorization server, key attestation for holder keysWallet-provider trust lists

Wallets never present registration certificates; issuers and verifiers present theirs to wallets.

Where keys are stored (database, Vault, AWS KMS, HSM and others) is an operator decision: see KMS.