Version: v0.25.0 (Latest)
Configure mdoc VICAL and CWT status
mdoc verification answers three separate questions: is the document signer certified by an accepted issuing authority (DSC and IACA), which issuing authorities does a signed VICAL list, and what is the current status bit (CWT Token Status List). This journey configures the VICAL and the CWT status publication.
Complete first: Publish status lists, Build trust domains and anchors.
Steps and why they come in this order
| Step | Why here |
|---|---|
| 1. Read the VICAL configuration and trust sources | The VICAL belongs to a provider anchor and becomes a trust-source revision. Read both before writing. |
| 2. Configure, validate and activate the VICAL | Saving the VICAL only creates a draft revision. Validation and activation are separate, deliberate steps. |
| 3. Publish CWT status for mdoc | The mdoc status list is independent of VICAL. Publish it with the one-bit mdoc profile and check the binary artifact. |
| Mechanism | Question | Data |
|---|---|---|
| DSC and IACA chain | Is the document signer certified by an accepted issuing authority? | X.509 certificates |
| VICAL | Which mdoc issuing authorities does this tenant accept, per a signed list? | CBOR/COSE signed list |
| CWT Token Status List | What is the current value at the status index stored in the mdoc? | COSE_Sign1 served as application/statuslist+cwt |
A valid status entry does not establish issuer trust, and an accepted issuer does not make a revoked credential valid.
Deeper reference
mdoc VICAL and CWT status has the captured VICAL requests and the console path for the CWT list.
Next
Return to the Credential issuance overview.