eu_broken_credimi_pid_trust_registry_infras ⚠ Broken
PID ProvidersETSI TS 119 602JSON / JAdES-B-B
⚠ Intentionally broken test fixture.
This Trusted List was generated deliberately non-conformant, with
5 defects listed below. It
exists so an EUDI implementation can register against a list that is known to
be bad and confirm its runtime detects the problem. A failing Trust
Inspector verdict on this list is the expected outcome, not a publication
error. Do not use it as a source of trust.
What is broken in this list
| Defect | What this list does | What a conformant list does | Normative reference |
|---|---|---|---|
Non-strict timestampsnon_strict_timestamps |
Emit ListIssueDateTime and NextUpdate with fractional seconds, violating the clause 6.1.3 lexical form. | ListIssueDateTime and NextUpdate are written as YYYY-MM-DDThh:mm:ssZ, with whole seconds and no fractional part. | ETSI TS 119 602 V1.1.1, clause 6.1.3 (date-time lexical form) Applied before signing. Expected Inspector rules: ts119602.syntax.date_time, ts119602.scheme.issue_time, ts119602.scheme.next_update, json_lote.dates.issue_valid, json_lote.dates.next_update_valid |
Scheme name without territoryscheme_name_without_territory |
Emit SchemeName without the SchemeTerritory prefix required by clause 6.3.6. | Each SchemeName value is prefixed with the scheme territory and a colon, for example EU:My List. | ETSI TS 119 602 V1.1.1, clause 6.3.6 (SchemeName) Applied before signing. Expected Inspector rule: ts119602.scheme.name |
Missing policy or legal noticemissing_policy_or_legal_notice |
Omit PolicyOrLegalNotice. | PolicyOrLegalNotice carries either a LoTEPolicy URI or a LoTELegalNotice, never both. | ETSI TS 119 602 V1.1.1, clause 6.3.11 (PolicyOrLegalNotice) Applied before signing. Expected Inspector rules: ts119602.scheme.policy_or_legal_notice, ts119602.structure.scheme_information_presence |
Operator without emailmissing_operator_email |
Publish only a website URI for the scheme operator, with no mailto URI. | The scheme operator's electronic address includes a mailto: URI alongside any website URI. | ETSI TS 119 602 V1.1.1, clause 6.3.4 (SchemeOperatorAddress) Applied before signing. Expected Inspector rule: ts119602.scheme.operator_address |
JAdES without signing timejades_without_signing_time |
Omit the iat protected header, so the signature is not JAdES Baseline B. | The claimed signing time is carried in the iat protected header as an integer NumericDate. | ETSI TS 119 182-1, clause 5.2.1 (JAdES Baseline B signing time) Applied after signing. Expected Inspector rules: json_lote.signature.jades_signing_time, json_lote.signature.jades_baseline_b, ts119602.profile.pub_eaa_providers.signature |
Each defect cites the clause it violates. The artifact format is JSON / Compact JAdES. Cascading failures are expected: one mutation can trip several Inspector rules. Each version page records the expected failures against the ones actually reported.
Trust not evaluated. Signatures are verified cryptographically but signer trust is not evaluated by this tool.
| Sequence | Issue Date | Next Update | Signature | Open |
|---|---|---|---|---|
| 1 | 2026-08-05T09:48:23.000Z | 2027-02-05T09:48:23.000Z | ✅ valid | JSON JAdES |