Build trust domains and anchors
A trust domain holds the public evidence a verifier accepts: anchors such as issuer certificates, DIDs or IACA roots, each admitted for specific questions. This journey builds the domains; binding them to the verifier and its queries is the next journey.
Complete first: Onboard a tenant.
Steps and why they come in this order
| Step | Why here |
|---|---|
| 1. Review existing trust domains | Provisioning seeds a domain for the tenant own issuer material. See what exists and who consumes it before adding more. |
| 2. Create and activate a domain | Anchors live inside a domain, and resolution requires ACTIVE, so the domain comes first. |
| 3. Add and maintain anchors | An anchor is the evidence itself. It must exist before any admission can say what it may answer. |
| 4. Grant admission classes | Admission is the decision that lets an anchor answer a usage. Grant only what the consuming usage needs. |
| 5. Configure an mdoc VICAL | Only for mdoc: the VICAL belongs to a provider anchor whose signer and issuer anchors already hold their admissions. |
Usages and admission classes
An anchor participates in a decision only when it holds the admission class the usage requires. Adding a certificate to a domain is not enough.
| Usage | Question | Admission class |
|---|---|---|
CREDENTIAL_ISSUER_TRUST | May this issuer have issued the presented credential? | CREDENTIAL_ISSUER |
WALLET_PROVIDER_ESTABLISHMENT | Is this wallet from an accepted wallet provider? | WALLET_PROVIDER |
VERIFIER_TRUST | Is this relying party one we release attributes to? | VERIFIER |
AUTHORIZATION_SERVER_TRUST | Did this token come from an admitted authorization server? | AUTHORIZATION_SERVER_SIGNER |
MDOC_VICAL_SIGNER and CATALOG_SIGNER admit the signature over a list; the entries inside are admitted
separately, normally as CREDENTIAL_ISSUER.
Every mutation is optimistically concurrent: GET returns a strong ETag, writes carry it in
If-Match, a missing header returns 428 and a stale one 412.
Deeper reference
Trust domains covers ETSI trust sources, LoTE sources,
catalogs and the 23 Trust Domains and Trust Lists Postman folder with captured requests.
Next journey
Continue with Bind trust and queries.