A credential issued on a machine whose clock was one second ahead was "not yet valid" at a verifier synchronized by NTP: measured on
2026-09-30 through the Aere Cloud identity route, the first time a credential was issued on one machine and judged on another.
Starts (a credential's and a status list's validFrom, a delegation's notBefore) are now accepted up to 60 s in the verifier's future
(verifyPresentation clockSkewS, 0..600); a revocation dated up to 60 s ahead already applies; ends (validUntil, notAfter) get no
allowance, since that would extend a validity.
Tests: identity 44/44, negative control 49/49.
- verify: --at <RFC 3339 UTC> judges on that clock (the verifier's clock in any case), so a verdict given at one moment can be checked
again later with the same result; a broken --trust-issuer or --max-age exits 2 with the reason instead of failing without a verdict;
the JSON result names the subject (type, credential, issuer, holder, presenter, delegations) when no check failed
- comply: --json [--with-record] prints the result and the record in one object; with --at the record's time is the same, so the same
command gives the same record byte for byte; a refused policy exits 2 with its reason
- Aere Cloud runs this command line unmodified behind POST /v1/identity/verify and POST /v1/compliance/check
Tests: identity 43/43, negative control 46/46.
- verify-consistency without --signer now says whether each head is signed and by which key, and that no expected signer was
checked (verify-inclusion already did; the README said the output does)
- openMessage opens nothing without a replay store (seen: an object with has/add that keeps the ids for at least maxAgeS);
before, the same signed and sealed message could be opened any number of times when no store was given
Tests: verify-layer tree 20/20, negative control 14/14; sidecar 44/44, 9/9; travel rule 19/19, negative control 19/19.