six fresh local lanes · one read-only GLEIF lane · zero egress

Issue what we can. Make the missing authority visible.

This laboratory creates fresh private artifacts in six lanes, verifies bundled GLEIF testnet evidence in a separate read-only lane, runs the implemented chain and signature checks, attacks the trust boundaries, and signs the resulting evidence. Each lane reports technical and recognition verdicts separately.

the non-negotiable distinction

We can manufacture artifacts. We cannot manufacture authority.

The demo really does

  • Generate profile-specific CA and signing keys in memory
  • Issue X.509, mdoc, SD-JWT, KERI/ACDC, JWS, and signed-list artifacts
  • Complete an in-memory TLS 1.3 mutual-authentication handshake using local QKD-identity test certificates; request and consume no QKD key
  • Walk every configured anchor and reject wrong-root, tamper, holder, revocation, replay, and scope attacks
  • Sign one public manifest containing fingerprints, digests, checks, control results, gates, and verdicts—never private keys, raw credentials, bearer tokens, or QKD key material

The demo cannot self-grant

  • Browser-default public trust or a qualified QTSP service
  • Government PID/mDL authority or Member-State wallet registration
  • A GLEIF-issued role, QVI status, or production vLEI
  • OIDF/ETSI certification, live KME operation, or QKD origin
  • Legal effect merely because a certificate has the expected profile shape
closed-input issuance ceremony

Fresh keys in. Signed evidence out.

The endpoint accepts only the fixed full scenario. It accepts no caller URL, credential, certificate, key, claim set, or policy. Nothing contacts a CA, wallet, registrar, KME, or external network.

Ready.
negative controls

A trust walk is useful only when shortcuts fail.

Each attack runs on an isolated branch and causes no external side effect.

Run the ceremony to load the attack matrix.

No request sent.
external recognition gates

What external recognition still requires.

These gates are prerequisites, not automatic substitutions. Official integration can also require different profiles, audits, status services, key custody, operations, contracts, and onboarding.

Run the ceremony to see every external gate.