Skip to content

Add two-TS Transparent Statement: Microsoft CCF dev + ASG RFC 9162 SHA-256 - #4

Open
StevenMih wants to merge 1 commit into
ietf-wg-scitt:mainfrom
action-state-group:feat/aac-ccf-asg-two-receipt-transparent-statement
Open

Add two-TS Transparent Statement: Microsoft CCF dev + ASG RFC 9162 SHA-256#4
StevenMih wants to merge 1 commit into
ietf-wg-scitt:mainfrom
action-state-group:feat/aac-ccf-asg-two-receipt-transparent-statement

Conversation

@StevenMih

Copy link
Copy Markdown
Contributor

Summary

Adds a Transparent Statement carrying receipts from two independent Transparency Services with different receipt profiles, following the pattern established by cose-hash-envelope-0-with-microsoft-mst-and-datatrails-mmr-receipts.scitt.

As noted during IETF 126 / Vienna 2026 interop: receipt profiles can be used in conjunction as well as in isolation. This is a second instance of that pattern with a different TS pair.

New file:

transparent-statements/aac-interop-es256-with-microsoft-ccf-dev-and-asg-rfc9162-receipts.scitt

Statement

  • Algorithm: ES256, issuer: did:x509 (Amaury Chamayou / Microsoft)
    • Content type: application/json
    • Statement SHA-256 (leaf entry): 02ec7822cd91641c74ee0d125ad9b89fc6961400c6efb69ec9aff65f3b23d567
    • Source: achamayou/scitt-ccf-ledger branch produce-ccf-profile-receipts-for-capsule

Receipts (unprotected header key 394)

Index TS Profile Alg Verified
0 Microsoft CCF dev node ccf.v1 / vds=2 / txid 2.15 ES384 ok=True
1 Action State Group RFC 9162 SHA-256 / vds=1 EdDSA ok=True

The Microsoft receipt is from a CCF dev node, not a production deployment.

Verification

Both receipts verified with scitt_cose.verify_receipt before submission. Full interop artifacts and three-receipt verify output are in action-state-group/scitt-cose at interop/ccf/shared-vector.json (version 2).

Suggested reviewer: @achamayou

ES256/did:x509 Signed Statement made transparent in two independent
Transparency Services: Microsoft CCF dev node (ccf.v1 / vds=2 / ES384)
and Action State Group (RFC 9162 SHA-256 / vds=1 / EdDSA).

Both receipts are embedded in the unprotected header under key 394,
following the pattern of the existing cose-hash-envelope-0 example.

Statement SHA-256 (leaf entry):
  02ec7822cd91641c74ee0d125ad9b89fc6961400c6efb69ec9aff65f3b23d567

Transparent statement SHA-256:
  aa9e2e7f5d62b501dbd2f2d3179e8f9aac5bde91009441d6ba872b94f0de2597

Both receipts verified ok=True with scitt_cose.verify_receipt before
submission. CCF receipt is from a dev node — not a production deployment.

Produced during IETF 126 / Vienna 2026 cross-implementation interop
(draft-mih-scitt-agent-action-capsule). Full interop artifacts and
verify steps in action-state-group/scitt-cose interop/ccf/.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants