it_broken_credimi_eaa_qeaa_trust_registry_i ⚠ Broken
EAA ProvidersQEAA ProvidersETSI TS 119 612XML / XAdES-B-B
⚠ Intentionally broken test fixture.
This Trusted List was generated deliberately non-conformant, with
5 defects listed below. It
exists so an EUDI implementation can register against a list that is known to
be bad and confirm its runtime detects the problem. A failing Trust
Inspector verdict on this list is the expected outcome, not a publication
error. Do not use it as a source of trust.
What is broken in this list
| Defect | What this list does | What a conformant list does | Normative reference |
|---|---|---|---|
Missing scheme information URImissing_scheme_information_uri |
Delete the whole SchemeInformationURI element. It is a mandatory member of the SchemeInformation sequence, so the document no longer validates against the pinned XSD. | SchemeInformationURI is present, in sequence order, and carries a language-tagged URI. | ETSI TS 119 612 V2.4.1, clause 5.3.7 (SchemeInformationURI) Applied before signing. Expected Inspector rules: schema.xsd, structure.scheme_information_uri, ts119612.scheme.information_uri |
Missing policy or legal noticemissing_policy_or_legal_notice |
Delete the whole PolicyOrLegalNotice element. | PolicyOrLegalNotice carries a TSLPolicy URI or a TSLLegalNotice for the scheme. | ETSI TS 119 612 V2.4.1, clause 5.3.11 (PolicyOrLegalNotice) Applied before signing. Expected Inspector rule: ts119612.scheme.policy_or_legal_notice |
PEM service certificatepem_service_certificate |
Re-armour every X509Certificate in a ServiceDigitalIdentity as PEM, including the BEGIN/END lines, so the base64Binary content no longer decodes to a certificate. | X509Certificate carries the Base64 DER encoding of the certificate, with no PEM armour. | ETSI TS 119 612 V2.4.1, clause 5.5.3 (ServiceDigitalIdentity) Applied before signing. Expected Inspector rule: schema.xsd |
Expired NextUpdateexpired_next_update |
Rewrite NextUpdate to one day before ListIssueDateTime, so the list is stale at the moment it is issued. | NextUpdate is later than ListIssueDateTime and at most six months after it. | ETSI TS 119 612 V2.4.1, clause 5.3.15 (NextUpdate) Applied before signing. Expected Inspector rules: dates.next_after_issue, ts119612.scheme.next_update |
Incorrect signing certificateincorrect_signing_certificate |
Re-sign with a CA certificate: basicConstraints CA:TRUE and a key usage of keyCertSign and cRLSign, with the correct subject. The signature verifies cryptographically, which is what separates this defect from broken_xades_signature. | The Trusted List is signed by an end-entity certificate stating basicConstraints CA:FALSE and a key usage limited to digitalSignature and/or contentCommitment. | ETSI TS 119 612 V2.4.1, clause 5.7 and Annex B (TLSO signing certificate) Applied after signing. Expected Inspector rules: ts119612.signature.certificate.basic_constraints, ts119612.signature.certificate.key_usage |
Each defect cites the clause it violates. The artifact format is XML / XAdES-B-B. Cascading failures are expected: one mutation can trip several Inspector rules. Each version page records the expected failures against the ones actually reported.
Trust not evaluated. Signatures are verified cryptographically but signer trust is not evaluated by this tool.
| Sequence | Issue Date | Next Update | Signature | Open |
|---|---|---|---|---|
| 1 | 2026-08-05T10:42:45Z | 2026-08-04T10:42:45Z | ✅ valid | XML |