This app is part of Credimi Extras. Automate all your EUDI testing with Credimi

eu_broken_credimi_pid_trust_registry_infras ⚠ Broken

PID ProvidersETSI TS 119 602JSON / JAdES-B-B
⚠ Intentionally broken test fixture. This Trusted List was generated deliberately non-conformant, with 5 defects listed below. It exists so an EUDI implementation can register against a list that is known to be bad and confirm its runtime detects the problem. A failing Trust Inspector verdict on this list is the expected outcome, not a publication error. Do not use it as a source of trust.

What is broken in this list

DefectWhat this list doesWhat a conformant list doesNormative reference
Non-strict timestamps
non_strict_timestamps
Emit ListIssueDateTime and NextUpdate with fractional seconds, violating the clause 6.1.3 lexical form. ListIssueDateTime and NextUpdate are written as YYYY-MM-DDThh:mm:ssZ, with whole seconds and no fractional part. ETSI TS 119 602 V1.1.1, clause 6.1.3 (date-time lexical form)
Applied before signing. Expected Inspector rules: ts119602.syntax.date_time, ts119602.scheme.issue_time, ts119602.scheme.next_update, json_lote.dates.issue_valid, json_lote.dates.next_update_valid
Scheme name without territory
scheme_name_without_territory
Emit SchemeName without the SchemeTerritory prefix required by clause 6.3.6. Each SchemeName value is prefixed with the scheme territory and a colon, for example EU:My List. ETSI TS 119 602 V1.1.1, clause 6.3.6 (SchemeName)
Applied before signing. Expected Inspector rule: ts119602.scheme.name
Missing policy or legal notice
missing_policy_or_legal_notice
Omit PolicyOrLegalNotice. PolicyOrLegalNotice carries either a LoTEPolicy URI or a LoTELegalNotice, never both. ETSI TS 119 602 V1.1.1, clause 6.3.11 (PolicyOrLegalNotice)
Applied before signing. Expected Inspector rules: ts119602.scheme.policy_or_legal_notice, ts119602.structure.scheme_information_presence
Operator without email
missing_operator_email
Publish only a website URI for the scheme operator, with no mailto URI. The scheme operator's electronic address includes a mailto: URI alongside any website URI. ETSI TS 119 602 V1.1.1, clause 6.3.4 (SchemeOperatorAddress)
Applied before signing. Expected Inspector rule: ts119602.scheme.operator_address
JAdES without signing time
jades_without_signing_time
Omit the iat protected header, so the signature is not JAdES Baseline B. The claimed signing time is carried in the iat protected header as an integer NumericDate. ETSI TS 119 182-1, clause 5.2.1 (JAdES Baseline B signing time)
Applied after signing. Expected Inspector rules: json_lote.signature.jades_signing_time, json_lote.signature.jades_baseline_b, ts119602.profile.pub_eaa_providers.signature

Each defect cites the clause it violates. The artifact format is JSON / Compact JAdES. Cascading failures are expected: one mutation can trip several Inspector rules. Each version page records the expected failures against the ones actually reported.

Trust not evaluated. Signatures are verified cryptographically but signer trust is not evaluated by this tool.
SequenceIssue DateNext UpdateSignatureOpen
1 2026-08-05T09:48:23.000Z 2027-02-05T09:48:23.000Z ✅ valid JSON JAdES