it_broken_credimi_eaa_qeaa_trust_registry_i - Version 1 ⚠ Broken
This is the latest version. It is also served at the stable URLs
/lists/it_broken_credimi_eaa_qeaa_trust_registry_i/latest/trusted-list.xml and
/lists/it_broken_credimi_eaa_qeaa_trust_registry_i/latest/trusted-list.sha2.
missing_scheme_information_uri, missing_policy_or_legal_notice, pem_service_certificate, expired_next_update, incorrect_signing_certificate.
A failing Trust Inspector verdict below is the expected outcome, not a
publication error.Negative fixture
| Fixture mode | intentionally-broken |
|---|---|
| Standard | TS 119 612 |
| Format | XML / XAdES-B-B |
| Mutation stages | before signingafter signing |
| Expected Inspector failures | dates.next_after_issueschema.xsdstructure.scheme_information_urits119612.scheme.information_urits119612.scheme.next_updatets119612.scheme.policy_or_legal_noticets119612.signature.certificate.basic_constraintsts119612.signature.certificate.key_usage |
| Actual Inspector failures | signature.signer_subject.organization: The signer subject organization does not equal the corresponding scheme metadata.ts119612.signature.certificate.key_usage: The TLSO certificate KeyUsage shall contain digitalSignature and/or nonRepudiation and no other usage.ts119612.signature.certificate.basic_constraints: The TLSO certificate BasicConstraints shall indicate CA=false.schema.xsd: Pinned ETSI TS 119 612 V2.4.1 XML Schema validation failed with xmllint.structure.scheme_information.child_cardinality: Direct SchemeInformation child cardinality does not satisfy clause 5.3.ts119612.scheme.information_uri: Scheme information URI shall contain non-empty URI values with valid language tags and absolute URIs.ts119612.scheme.policy_or_legal_notice: PolicyOrLegalNotice is missing from its direct normative position.ts119612.scheme.next_update: NextUpdate shall use strict UTC syntax, follow ListIssueDateTime, and not exceed six calendar months.structure.scheme_information_uri: SchemeInformationURI exists.dates.next_after_issue: NextUpdate is after ListIssueDateTime.ts119612.service.1.1.identity_equivalence: Service identity representations are not mutually equivalent.ts119612.service.2.1.identity_equivalence: Service identity representations are not mutually equivalent. |
| Matched | dates.next_after_issueschema.xsdstructure.scheme_information_urits119612.scheme.information_urits119612.scheme.next_updatets119612.scheme.policy_or_legal_noticets119612.signature.certificate.basic_constraintsts119612.signature.certificate.key_usage |
| Expected but not reported | none |
| Additional failures | signature.signer_subject.organizationstructure.scheme_information.child_cardinalityts119612.service.identity_equivalence |
| Expected local failures | local.freshnesslocal.signing_certificate.profilelocal.xml.schema |
| Actual local failures | local.xml.schemalocal.signing_certificate.profilelocal.freshness |
| Expected locally but not reported | none |
Mutations
| Defect | Stage | Status | Detail |
|---|---|---|---|
missing_scheme_information_uri | before signing | applied | Removed the mandatory SchemeInformationURI element. |
missing_policy_or_legal_notice | before signing | applied | Removed PolicyOrLegalNotice. |
pem_service_certificate | before signing | applied | Re-armoured 2 service certificate(s) as PEM. |
expired_next_update | before signing | applied | NextUpdate set to 2026-08-04T10:42:45Z, one day before the issue time. |
incorrect_signing_certificate | after signing | applied | The substitute signer is a CA certificate: basicConstraints CA:TRUE, keyUsage keyCertSign and cRLSign. |
Cascading failures are expected: one mutation can trip several rules. Additional failures are listed rather than hidden so a drifting Inspector rule set stays visible. An Inspector result that is unavailable, not applicable or empty is never counted as a pass.
List Information
| Trusted List | it_broken_credimi_eaa_qeaa_trust_registry_i |
|---|---|
| TSL sequence number | 1 |
| TSL version identifier | 6 |
| TSL type | http://uri.etsi.org/TrstSvc/TrustedList/TSLType/EUgeneric |
| Status determination | http://uri.etsi.org/TrstSvc/TrustedList/StatusDetn/EUappropriate |
| Scheme operator | Broken Credimi EAA/QEAA Trust Registry Infrastructure |
| Scheme name | IT:BROKEN CREDIMI - EAA/QEAA Providers |
| Scheme territory | IT |
| Historical information period | 65535 |
| Issued | 2026-08-05T10:42:45Z |
| Next update | 2026-08-04T10:42:45Z |
Signature & Validation
| Signature valid | ✅ Yes |
|---|---|
| ETSI schema valid | ❌ No |
| Signer trust | not_evaluated — this publisher builds no certification path and makes no trust decision |
| Signature | XAdES-B-B, verified locally |
| Signature algorithm | http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha256 |
| Signing time | 2026-08-05T10:42:45Z |
| Freshness | stale: NextUpdate 2026-08-04T10:42:45Z is not later than ListIssueDateTime 2026-08-05T10:42:45Z. NextUpdate 2026-08-04T10:42:45Z has already passed at publication time. |
Signing Certificate
| Subject | CN=Intentionally Broken Trusted List Signer, C=IT, O=Broken Credimi EAA QEAA Trust Registry Infrastructure |
|---|---|
| Issuer | CN=Intentionally Broken Trusted List Signer, C=IT, O=Broken Credimi EAA QEAA Trust Registry Infrastructure |
| Valid from | Aug 5 10:42:45 2026 GMT |
| Valid to | Aug 5 10:42:45 2027 GMT |
| Certificate SHA-256 | 83c165d99f04ecc46064b15b39a467f2b32ff0ac44c65ee5a0e9a5e5cec21725 |
| Certificate profile | does not meet the profile: The signing certificate subject organisation (O) is "Broken Credimi EAA QEAA Trust Registry Infrastructure", but the Scheme Operator Name is "Broken Credimi EAA/QEAA Trust Registry Infrastructure". They must be equal. The signing certificate asserts basicConstraints CA:TRUE. A Trusted List signing certificate must state CA:FALSE. The signing certificate keyUsage asserts keyCertSign, cRLSign. A Trusted List signing certificate may assert only digitalSignature and/or contentCommitment. |
Trust Inspector
Fail
| Standard assessed | TS 119 612 |
|---|---|
| Detected artifact | ts119612_xml_tsl |
| TS 119 612 applicability | applicable |
| Conformance level | non_conformant |
| Service types | http://uri.etsi.org/TrstSvc/Svctype/EAAhttp://uri.etsi.org/TrstSvc/Svctype/EAA/Q |
| Checks | 140 pass, 12 fail, 4 warn, 22 n/a, 7 not checked |
| Evaluated | 2026-08-05T10:42:45.980Z |
| Inspector | https://trust-inspector.credimi.io |
- signature.signer_subject.organization: The signer subject organization does not equal the corresponding scheme metadata.
- ts119612.signature.certificate.key_usage: The TLSO certificate KeyUsage shall contain digitalSignature and/or nonRepudiation and no other usage.
- ts119612.signature.certificate.basic_constraints: The TLSO certificate BasicConstraints shall indicate CA=false.
- schema.xsd: Pinned ETSI TS 119 612 V2.4.1 XML Schema validation failed with xmllint.
- structure.scheme_information.child_cardinality: Direct SchemeInformation child cardinality does not satisfy clause 5.3.
- ts119612.scheme.information_uri: Scheme information URI shall contain non-empty URI values with valid language tags and absolute URIs.
- ts119612.scheme.policy_or_legal_notice: PolicyOrLegalNotice is missing from its direct normative position.
- ts119612.scheme.next_update: NextUpdate shall use strict UTC syntax, follow ListIssueDateTime, and not exceed six calendar months.
- structure.scheme_information_uri: SchemeInformationURI exists.
- dates.next_after_issue: NextUpdate is after ListIssueDateTime.
- ts119612.service.1.1.identity_equivalence: Service identity representations are not mutually equivalent.
- ts119612.service.2.1.identity_equivalence: Service identity representations are not mutually equivalent.
Entities & Services
No trusted service providers are recorded in this version.
2 trusted service provider(s), 2 service(s). Allowed profiles: eaa-providers, qeaa-providers
Downloads
XML SHA-256 digest Inspector report
The XML is served as application/vnd.etsi.tsl+xml; its XAdES-B-B
signature is inside the document. The .sha2 file is the SHA-256
of the exact published XML bytes. Publication
manifest.
Artifact Hashes
| XML SHA-256 | c8faf290ec8766a6b2398b01784cfb82d83d593ec714128641d20de88885633b |
|---|---|
| .sha2 published | c8faf290ec8766a6b2398b01784cfb82d83d593ec714128641d20de88885633b — matches the XML |