Skip to main content
Version: v0.25.0 (Latest)

Build trust domains and anchors

A trust domain holds the public evidence a verifier accepts: anchors such as issuer certificates, DIDs or IACA roots, each admitted for specific questions. This journey builds the domains; binding them to the verifier and its queries is the next journey.

Complete first: Onboard a tenant.

Steps and why they come in this order​

StepWhy here
1. Review existing trust domainsProvisioning seeds a domain for the tenant own issuer material. See what exists and who consumes it before adding more.
2. Create and activate a domainAnchors live inside a domain, and resolution requires ACTIVE, so the domain comes first.
3. Add and maintain anchorsAn anchor is the evidence itself. It must exist before any admission can say what it may answer.
4. Grant admission classesAdmission is the decision that lets an anchor answer a usage. Grant only what the consuming usage needs.
5. Configure an mdoc VICALOnly for mdoc: the VICAL belongs to a provider anchor whose signer and issuer anchors already hold their admissions.

Usages and admission classes​

An anchor participates in a decision only when it holds the admission class the usage requires. Adding a certificate to a domain is not enough.

UsageQuestionAdmission class
CREDENTIAL_ISSUER_TRUSTMay this issuer have issued the presented credential?CREDENTIAL_ISSUER
WALLET_PROVIDER_ESTABLISHMENTIs this wallet from an accepted wallet provider?WALLET_PROVIDER
VERIFIER_TRUSTIs this relying party one we release attributes to?VERIFIER
AUTHORIZATION_SERVER_TRUSTDid this token come from an admitted authorization server?AUTHORIZATION_SERVER_SIGNER

MDOC_VICAL_SIGNER and CATALOG_SIGNER admit the signature over a list; the entries inside are admitted separately, normally as CREDENTIAL_ISSUER.

Every mutation is optimistically concurrent: GET returns a strong ETag, writes carry it in If-Match, a missing header returns 428 and a stale one 412.

Deeper reference​

Trust domains covers ETSI trust sources, LoTE sources, catalogs and the 23 Trust Domains and Trust Lists Postman folder with captured requests.

Next journey​

Continue with Bind trust and queries.