This app is part of Credimi Extras. Automate all your EUDI testing with Credimi

it_broken_credimi_eaa_qeaa_trust_registry_i ⚠ Broken

EAA ProvidersQEAA ProvidersETSI TS 119 612XML / XAdES-B-B
⚠ Intentionally broken test fixture. This Trusted List was generated deliberately non-conformant, with 5 defects listed below. It exists so an EUDI implementation can register against a list that is known to be bad and confirm its runtime detects the problem. A failing Trust Inspector verdict on this list is the expected outcome, not a publication error. Do not use it as a source of trust.

What is broken in this list

DefectWhat this list doesWhat a conformant list doesNormative reference
Missing scheme information URI
missing_scheme_information_uri
Delete the whole SchemeInformationURI element. It is a mandatory member of the SchemeInformation sequence, so the document no longer validates against the pinned XSD. SchemeInformationURI is present, in sequence order, and carries a language-tagged URI. ETSI TS 119 612 V2.4.1, clause 5.3.7 (SchemeInformationURI)
Applied before signing. Expected Inspector rules: schema.xsd, structure.scheme_information_uri, ts119612.scheme.information_uri
Missing policy or legal notice
missing_policy_or_legal_notice
Delete the whole PolicyOrLegalNotice element. PolicyOrLegalNotice carries a TSLPolicy URI or a TSLLegalNotice for the scheme. ETSI TS 119 612 V2.4.1, clause 5.3.11 (PolicyOrLegalNotice)
Applied before signing. Expected Inspector rule: ts119612.scheme.policy_or_legal_notice
PEM service certificate
pem_service_certificate
Re-armour every X509Certificate in a ServiceDigitalIdentity as PEM, including the BEGIN/END lines, so the base64Binary content no longer decodes to a certificate. X509Certificate carries the Base64 DER encoding of the certificate, with no PEM armour. ETSI TS 119 612 V2.4.1, clause 5.5.3 (ServiceDigitalIdentity)
Applied before signing. Expected Inspector rule: schema.xsd
Expired NextUpdate
expired_next_update
Rewrite NextUpdate to one day before ListIssueDateTime, so the list is stale at the moment it is issued. NextUpdate is later than ListIssueDateTime and at most six months after it. ETSI TS 119 612 V2.4.1, clause 5.3.15 (NextUpdate)
Applied before signing. Expected Inspector rules: dates.next_after_issue, ts119612.scheme.next_update
Incorrect signing certificate
incorrect_signing_certificate
Re-sign with a CA certificate: basicConstraints CA:TRUE and a key usage of keyCertSign and cRLSign, with the correct subject. The signature verifies cryptographically, which is what separates this defect from broken_xades_signature. The Trusted List is signed by an end-entity certificate stating basicConstraints CA:FALSE and a key usage limited to digitalSignature and/or contentCommitment. ETSI TS 119 612 V2.4.1, clause 5.7 and Annex B (TLSO signing certificate)
Applied after signing. Expected Inspector rules: ts119612.signature.certificate.basic_constraints, ts119612.signature.certificate.key_usage

Each defect cites the clause it violates. The artifact format is XML / XAdES-B-B. Cascading failures are expected: one mutation can trip several Inspector rules. Each version page records the expected failures against the ones actually reported.

Trust not evaluated. Signatures are verified cryptographically but signer trust is not evaluated by this tool.
SequenceIssue DateNext UpdateSignatureOpen
1 2026-08-05T10:42:45Z 2026-08-04T10:42:45Z ✅ valid XML