Commit Graph

3 Commits

Author SHA1 Message Date
Aere Network
5f1e60b8d2 identity: verify-sdjwt on the command line (an SD-JWT+KB checked with the issuer key you give; Aere Cloud runs it behind POST /v1/identity/sd-jwt/verify)
The issuer key (a public JWK, or the public keys of an AERE identity) is checked first: one that cannot be read, is private, or is not
a key for the algorithm asked exits 2 with the reason, instead of reporting the token INVALID. --json prints compact JSON (indented
output grew with the square of the claims' nesting depth). --at judges at a given time, as for verify. Test on the RFC 9901 example
presentation: valid at its own time, invalid now, a private key refused. Tests: SD-JWT 23/23, negative control 28/28; identity 44/44,
negative control 49/49.
2026-09-30 13:17:07 +03:00
Aere Network
0b56d8e5df identity: 60 s of clock allowance on starts (validFrom, notBefore) and, the careful way, on revocations; none on ends
A credential issued on a machine whose clock was one second ahead was "not yet valid" at a verifier synchronized by NTP: measured on
2026-09-30 through the Aere Cloud identity route, the first time a credential was issued on one machine and judged on another.
Starts (a credential's and a status list's validFrom, a delegation's notBefore) are now accepted up to 60 s in the verifier's future
(verifyPresentation clockSkewS, 0..600); a revocation dated up to 60 s ahead already applies; ends (validUntil, notAfter) get no
allowance, since that would extend a validity.

Tests: identity 44/44, negative control 49/49.
2026-09-30 11:36:02 +03:00
Aere Network
b5e1628265 identity: post-quantum credentials with selective disclosure, delegation that can only narrow, revocation and an issuer status list, checked offline from the files 2026-09-30 09:18:53 +03:00