This app is part of Credimi Extras. Automate all your EUDI testing with Credimi

it_broken_credimi_eaa_qeaa_trust_registry_i - Version 1 ⚠ Broken

EAA ProvidersQEAA ProvidersETSI TS 119 612XML / XAdES-B-B

This is the latest version. It is also served at the stable URLs /lists/it_broken_credimi_eaa_qeaa_trust_registry_i/latest/trusted-list.xml and /lists/it_broken_credimi_eaa_qeaa_trust_registry_i/latest/trusted-list.sha2.

⚠ Intentionally broken test fixture. This version was generated with 5 deliberate defects: missing_scheme_information_uri, missing_policy_or_legal_notice, pem_service_certificate, expired_next_update, incorrect_signing_certificate. A failing Trust Inspector verdict below is the expected outcome, not a publication error.

Negative fixture

Fixture modeintentionally-broken
StandardTS 119 612
FormatXML / XAdES-B-B
Mutation stagesbefore signing
after signing
Expected Inspector failuresdates.next_after_issue
schema.xsd
structure.scheme_information_uri
ts119612.scheme.information_uri
ts119612.scheme.next_update
ts119612.scheme.policy_or_legal_notice
ts119612.signature.certificate.basic_constraints
ts119612.signature.certificate.key_usage
Actual Inspector failuressignature.signer_subject.organization: The signer subject organization does not equal the corresponding scheme metadata.
ts119612.signature.certificate.key_usage: The TLSO certificate KeyUsage shall contain digitalSignature and/or nonRepudiation and no other usage.
ts119612.signature.certificate.basic_constraints: The TLSO certificate BasicConstraints shall indicate CA=false.
schema.xsd: Pinned ETSI TS 119 612 V2.4.1 XML Schema validation failed with xmllint.
structure.scheme_information.child_cardinality: Direct SchemeInformation child cardinality does not satisfy clause 5.3.
ts119612.scheme.information_uri: Scheme information URI shall contain non-empty URI values with valid language tags and absolute URIs.
ts119612.scheme.policy_or_legal_notice: PolicyOrLegalNotice is missing from its direct normative position.
ts119612.scheme.next_update: NextUpdate shall use strict UTC syntax, follow ListIssueDateTime, and not exceed six calendar months.
structure.scheme_information_uri: SchemeInformationURI exists.
dates.next_after_issue: NextUpdate is after ListIssueDateTime.
ts119612.service.1.1.identity_equivalence: Service identity representations are not mutually equivalent.
ts119612.service.2.1.identity_equivalence: Service identity representations are not mutually equivalent.
Matcheddates.next_after_issue
schema.xsd
structure.scheme_information_uri
ts119612.scheme.information_uri
ts119612.scheme.next_update
ts119612.scheme.policy_or_legal_notice
ts119612.signature.certificate.basic_constraints
ts119612.signature.certificate.key_usage
Expected but not reportednone
Additional failuressignature.signer_subject.organization
structure.scheme_information.child_cardinality
ts119612.service.identity_equivalence
Expected local failureslocal.freshness
local.signing_certificate.profile
local.xml.schema
Actual local failureslocal.xml.schema
local.signing_certificate.profile
local.freshness
Expected locally but not reportednone

Mutations

DefectStageStatusDetail
missing_scheme_information_uribefore signingappliedRemoved the mandatory SchemeInformationURI element.
missing_policy_or_legal_noticebefore signingappliedRemoved PolicyOrLegalNotice.
pem_service_certificatebefore signingappliedRe-armoured 2 service certificate(s) as PEM.
expired_next_updatebefore signingappliedNextUpdate set to 2026-08-04T10:42:45Z, one day before the issue time.
incorrect_signing_certificateafter signingappliedThe substitute signer is a CA certificate: basicConstraints CA:TRUE, keyUsage keyCertSign and cRLSign.

Cascading failures are expected: one mutation can trip several rules. Additional failures are listed rather than hidden so a drifting Inspector rule set stays visible. An Inspector result that is unavailable, not applicable or empty is never counted as a pass.

Trust not evaluated. Signatures are verified cryptographically but signer trust is not evaluated by this tool.

List Information

Trusted Listit_broken_credimi_eaa_qeaa_trust_registry_i
TSL sequence number1
TSL version identifier6
TSL typehttp://uri.etsi.org/TrstSvc/TrustedList/TSLType/EUgeneric
Status determinationhttp://uri.etsi.org/TrstSvc/TrustedList/StatusDetn/EUappropriate
Scheme operatorBroken Credimi EAA/QEAA Trust Registry Infrastructure
Scheme nameIT:BROKEN CREDIMI - EAA/QEAA Providers
Scheme territoryIT
Historical information period65535
Issued2026-08-05T10:42:45Z
Next update2026-08-04T10:42:45Z

Signature & Validation

Signature valid✅ Yes
ETSI schema valid❌ No
Signer trustnot_evaluated — this publisher builds no certification path and makes no trust decision
SignatureXAdES-B-B, verified locally
Signature algorithmhttp://www.w3.org/2001/04/xmldsig-more#ecdsa-sha256
Signing time2026-08-05T10:42:45Z
Freshnessstale: NextUpdate 2026-08-04T10:42:45Z is not later than ListIssueDateTime 2026-08-05T10:42:45Z. NextUpdate 2026-08-04T10:42:45Z has already passed at publication time.

Signing Certificate

SubjectCN=Intentionally Broken Trusted List Signer, C=IT, O=Broken Credimi EAA QEAA Trust Registry Infrastructure
IssuerCN=Intentionally Broken Trusted List Signer, C=IT, O=Broken Credimi EAA QEAA Trust Registry Infrastructure
Valid fromAug 5 10:42:45 2026 GMT
Valid toAug 5 10:42:45 2027 GMT
Certificate SHA-25683c165d99f04ecc46064b15b39a467f2b32ff0ac44c65ee5a0e9a5e5cec21725
Certificate profiledoes not meet the profile: The signing certificate subject organisation (O) is "Broken Credimi EAA QEAA Trust Registry Infrastructure", but the Scheme Operator Name is "Broken Credimi EAA/QEAA Trust Registry Infrastructure". They must be equal. The signing certificate asserts basicConstraints CA:TRUE. A Trusted List signing certificate must state CA:FALSE. The signing certificate keyUsage asserts keyCertSign, cRLSign. A Trusted List signing certificate may assert only digitalSignature and/or contentCommitment.

Trust Inspector

Fail

Standard assessedTS 119 612
Detected artifactts119612_xml_tsl
TS 119 612 applicabilityapplicable
Conformance levelnon_conformant
Service typeshttp://uri.etsi.org/TrstSvc/Svctype/EAA
http://uri.etsi.org/TrstSvc/Svctype/EAA/Q
Checks140 pass, 12 fail, 4 warn, 22 n/a, 7 not checked
Evaluated2026-08-05T10:42:45.980Z
Inspectorhttps://trust-inspector.credimi.io
  • signature.signer_subject.organization: The signer subject organization does not equal the corresponding scheme metadata.
  • ts119612.signature.certificate.key_usage: The TLSO certificate KeyUsage shall contain digitalSignature and/or nonRepudiation and no other usage.
  • ts119612.signature.certificate.basic_constraints: The TLSO certificate BasicConstraints shall indicate CA=false.
  • schema.xsd: Pinned ETSI TS 119 612 V2.4.1 XML Schema validation failed with xmllint.
  • structure.scheme_information.child_cardinality: Direct SchemeInformation child cardinality does not satisfy clause 5.3.
  • ts119612.scheme.information_uri: Scheme information URI shall contain non-empty URI values with valid language tags and absolute URIs.
  • ts119612.scheme.policy_or_legal_notice: PolicyOrLegalNotice is missing from its direct normative position.
  • ts119612.scheme.next_update: NextUpdate shall use strict UTC syntax, follow ListIssueDateTime, and not exceed six calendar months.
  • structure.scheme_information_uri: SchemeInformationURI exists.
  • dates.next_after_issue: NextUpdate is after ListIssueDateTime.
  • ts119612.service.1.1.identity_equivalence: Service identity representations are not mutually equivalent.
  • ts119612.service.2.1.identity_equivalence: Service identity representations are not mutually equivalent.

Entities & Services

No trusted service providers are recorded in this version.

2 trusted service provider(s), 2 service(s). Allowed profiles: eaa-providers, qeaa-providers

Downloads

XML SHA-256 digest Inspector report

The XML is served as application/vnd.etsi.tsl+xml; its XAdES-B-B signature is inside the document. The .sha2 file is the SHA-256 of the exact published XML bytes. Publication manifest.

Artifact Hashes

XML SHA-256c8faf290ec8766a6b2398b01784cfb82d83d593ec714128641d20de88885633b
.sha2 publishedc8faf290ec8766a6b2398b01784cfb82d83d593ec714128641d20de88885633b — matches the XML