Skip to content

Group trust metadata by contributor and generalize signatures - #14

Closed
jonathanhefner wants to merge 1 commit into
agent/signing-proposal-basefrom
agent/identity-keyed-trust-manifests
Closed

jonathanhefner wants to merge 1 commit into
agent/signing-proposal-basefrom
agent/identity-keyed-trust-manifests

Conversation

@jonathanhefner

@jonathanhefner jonathanhefner commented Sep 12, 2026 •

Copy link
Copy Markdown
Owner

Summary

Allow publishers, assessors, and federated registries to contribute trust metadata about the same artifact, with independent signatures over the fields each endorses.

Area Current design Proposed design
Trust metadata One entry.trustManifest entry.trustManifests[identity], each retaining its attestation and provenance arrays
Signatures Entry signature covers the whole Trust Manifest; separate root signature Separate signatures arrays on entries and the catalog root, selecting fields through arrays of keys
Artifact binding Release fields repeated in entry.trustManifest.subject Sign the entry’s release fields and entry.digest directly
Policy URLs Inside the signed Trust Manifest Shared entry fields; signing coverage follows the selected paths

Motivation

  • Independent contributions. A publisher can sign its source provenance while an assessor signs its audit evidence for the same release. If each selects its own Trust Manifest and the shared release fields, the assessor can update its evidence without invalidating the publisher’s signature. A registry can add its own contribution alongside both.
  • Flexible coverage. Signers can endorse entry extensions or other relevant fields. Catalog operators can sign Host Info through root signatures or endorse the complete catalog snapshot.
  • Reuse existing standards. Detached JWS and JCS authenticate selected paths, values, and timestamps. The existing did:web rules authenticate independent contributors while preserving the additional checks for publisher authority.

Rationale

ADR-0028 explains the construction and tradeoffs.

The schema, guides, mappings, examples, and threat model are updated together.

Notes

  • Dependencies: #108, #109, and #110.
  • Validation: Specification and strict documentation builds, example checks, and local signing tests.

@jonathanhefner
jonathanhefner force-pushed the agent/identity-keyed-trust-manifests branch from 5957e3f to 7d0ff84 Compare September 13, 2026 01:23
@jonathanhefner
jonathanhefner changed the base branch from main to agent/signing-proposal-base September 13, 2026 01:23
Comment thread adr/0028-identity-keyed-trust-manifests.md Outdated
Comment thread adr/0028-identity-keyed-trust-manifests.md Outdated
Comment thread adr/0028-identity-keyed-trust-manifests.md Outdated
Comment thread adr/0028-identity-keyed-trust-manifests.md Outdated
Comment thread adr/0028-identity-keyed-trust-manifests.md Outdated
Comment thread adr/0028-identity-keyed-trust-manifests.md Outdated
Comment thread adr/0028-identity-keyed-trust-manifests.md Outdated
Comment thread adr/0028-identity-keyed-trust-manifests.md Outdated
Comment thread adr/0028-identity-keyed-trust-manifests.md Outdated
Comment thread adr/0028-identity-keyed-trust-manifests.md Outdated
Comment thread specification/test-vectors/README.md Outdated
Comment thread specification/test-vectors/entry-signature.json Outdated
Comment thread tools/check_signatures.mjs Outdated
Comment thread adr/0027-did-web-entry-signature-profile.md Outdated
Comment thread adr/0028-identity-keyed-trust-manifests.md Outdated
Comment thread specification/ai-catalog.md
Comment thread specification/ai-catalog.md
Comment thread specification/ai-catalog.md Outdated
Comment thread specification/ai-catalog.md Outdated
Comment thread specification/ai-catalog.md Outdated
Comment thread adr/0027-did-web-entry-signature-profile.md Outdated
Comment thread adr/0027-did-web-entry-signature-profile.md Outdated
Comment thread adr/0028-identity-keyed-trust-manifests.md Outdated
Comment thread adr/0028-identity-keyed-trust-manifests.md Outdated
Comment thread docs/guides/adding-trust.md Outdated
Comment thread specification/ai-catalog.md Outdated
Comment thread specification/ai-catalog.md Outdated
Comment thread specification/ai-catalog.md Outdated
Comment thread specification/ai-catalog.md Outdated
Comment thread specification/trust-manifest-threat-model.md Outdated
Allow publishers, assessors, and registries to contribute independently
to the same entry. Identity-keyed Trust Manifests hold their claims,
while entry and catalog signatures select the fields each signer
endorses.

Use detached JWS over canonical paths, values, context, and timestamps.
Bind claims to shared entry release coordinates and digest without a
duplicated subject. Reuse did:web key verification while distinguishing
contributor attribution, publisher authority, and complete catalog
snapshot coverage.

Update the schema, examples, guides, distribution mappings, and threat
model together while retaining existing transport signing delegation.
@jonathanhefner
jonathanhefner force-pushed the agent/identity-keyed-trust-manifests branch from ec2f038 to 0fa896d Compare September 13, 2026 23:01
@jonathanhefner

Copy link
Copy Markdown
Owner Author

Submitted as Agent-Card#117.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant