KISC arch init
This commit is contained in:
506
ikt-arh-kultura-valodu-tehnologijas/mcpf/README.md
Normal file
506
ikt-arh-kultura-valodu-tehnologijas/mcpf/README.md
Normal file
@@ -0,0 +1,506 @@
|
||||
# KISC MCP Server - MCPF Integration Deployment Guide
|
||||
|
||||
**Project:** MCPF (MCP Trust Framework) Integration for KISC MCP Server
|
||||
**Target Server:** llm.kis.gov.lv
|
||||
**DID:** `did:web:llm.kis.gov.lv`
|
||||
**Date:** 2026-01-30
|
||||
|
||||
---
|
||||
|
||||
## 📋 Table of Contents
|
||||
|
||||
1. [Overview](#overview)
|
||||
2. [Package Contents](#package-contents)
|
||||
3. [Prerequisites](#prerequisites)
|
||||
4. [Part A: Local Implementation](#part-a-local-implementation)
|
||||
5. [Part B: VeriTrust Integration](#part-b-veritrust-integration)
|
||||
6. [Validation & Testing](#validation--testing)
|
||||
7. [Troubleshooting](#troubleshooting)
|
||||
|
||||
---
|
||||
|
||||
## Overview
|
||||
|
||||
This package integrates MCPF (MCP Trust Framework) into the KISC MCP Server, providing:
|
||||
|
||||
✅ **Cryptographic Identity** — `did:web:llm.kis.gov.lv` with Ed25519 signing
|
||||
✅ **Verifiable Credentials** — VeriTrust-issued MCPServerCredential
|
||||
✅ **Trust Metadata** — Discoverable at `/.well-known/mcp-trust-registry.json`
|
||||
✅ **Standards Compliance** — W3C DID Core, VC Data Model, MCPF Specification
|
||||
|
||||
---
|
||||
|
||||
## Package Contents
|
||||
|
||||
```
|
||||
kisc-mcpf-deploy/
|
||||
├── README.md # This file
|
||||
├── keypair-SECURE.json # ⚠️ PRIVATE KEY (secure handling!)
|
||||
├── public-key.json # Public key reference
|
||||
│
|
||||
├── wellknown/ # .well-known files for nginx
|
||||
│ ├── did.json # DID Document
|
||||
│ ├── jwks.json # JWK Set (public keys)
|
||||
│ ├── mcp-trust-registry.json # MCPF registry discovery
|
||||
│ ├── security.txt # RFC 9116 security contact
|
||||
│ ├── mcp/
|
||||
│ │ └── manifest.json # MCP server capabilities
|
||||
│ └── credentials/
|
||||
│ └── mcp-server.json # VC placeholder (VeriTrust will replace)
|
||||
│
|
||||
├── scripts/ # Deployment automation
|
||||
│ ├── deploy-wellknown.sh # Deploy .well-known to server
|
||||
│ ├── validate-endpoints.sh # Test all endpoints
|
||||
│ └── update-env.sh # Add MCPF_PRIVATE_KEY to .env
|
||||
│
|
||||
├── nginx/ # nginx configuration
|
||||
│ └── wellknown.conf # nginx config for .well-known
|
||||
│
|
||||
├── docs/ # Documentation
|
||||
│ ├── DEPLOYMENT.md # Step-by-step deployment
|
||||
│ ├── INTEGRATION.md # start.sh/status.sh updates
|
||||
│ └── TESTING.md # Validation procedures
|
||||
│
|
||||
└── veritrust/ # VeriTrust submission
|
||||
├── README-VERITRUST.md # Instructions for VeriTrust
|
||||
├── mcp-server-request.json # Credential request payload
|
||||
└── install-credential.sh # Install received VC
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## Prerequisites
|
||||
|
||||
Before deployment, ensure:
|
||||
|
||||
- [ ] SSH access to `llm.kis.gov.lv` (10.20.30.96)
|
||||
- [ ] Sudo privileges or ownership of `/opt/kisc-llm/`
|
||||
- [ ] POC stack running (`/opt/kisc-llm/poc/deploy/`)
|
||||
- [ ] nginx container (kisc-nginx) operational
|
||||
- [ ] Let's Encrypt certificates valid
|
||||
- [ ] Git access to `kisc-gov-lv/MCP-KISC-architecture`
|
||||
|
||||
---
|
||||
|
||||
## Part A: Local Implementation
|
||||
|
||||
### Step 1: Secure Private Key Storage
|
||||
|
||||
**⚠️ CRITICAL: Handle `keypair-SECURE.json` securely!**
|
||||
|
||||
```bash
|
||||
# On your local machine (NOT on server yet)
|
||||
cat keypair-SECURE.json
|
||||
# Contains: private_key_pem, public_key_pem, multibase, jwk_x
|
||||
|
||||
# Verify integrity
|
||||
sha256sum keypair-SECURE.json
|
||||
```
|
||||
|
||||
**DO NOT:**
|
||||
- ❌ Commit to Git
|
||||
- ❌ Send via unencrypted email
|
||||
- ❌ Store in Slack/Teams
|
||||
- ❌ Print to logs
|
||||
|
||||
**DO:**
|
||||
- ✅ Transfer via encrypted channel (scp with key auth, 1Password, etc.)
|
||||
- ✅ Store in `/opt/kisc-llm/poc/deploy/.env` only
|
||||
- ✅ Backup offline (encrypted USB/vault)
|
||||
- ✅ Document who has access
|
||||
|
||||
---
|
||||
|
||||
### Step 2: Deploy .well-known Files to Server
|
||||
|
||||
```bash
|
||||
# On llm.kis.gov.lv server
|
||||
|
||||
# 1. Create .well-known directory
|
||||
sudo mkdir -p /opt/kisc-llm/poc/deploy/.well-known/{mcp,credentials}
|
||||
sudo chown -R "$USER":"$USER" /opt/kisc-llm/poc/deploy/.well-known
|
||||
|
||||
# 2. Copy .well-known files
|
||||
cd /opt/kisc-llm/poc/deploy
|
||||
rsync -av /path/to/kisc-mcpf-deploy/wellknown/ .well-known/
|
||||
|
||||
# 3. Verify structure
|
||||
tree .well-known/
|
||||
# Expected:
|
||||
# .well-known/
|
||||
# ├── did.json
|
||||
# ├── jwks.json
|
||||
# ├── mcp-trust-registry.json
|
||||
# ├── security.txt
|
||||
# ├── mcp/
|
||||
# │ └── manifest.json
|
||||
# └── credentials/
|
||||
# └── mcp-server.json
|
||||
|
||||
# 4. Set permissions (read-only for nginx)
|
||||
chmod -R 644 .well-known/**/*
|
||||
find .well-known -type d -exec chmod 755 {} \;
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
### Step 3: Add Private Key to .env
|
||||
|
||||
```bash
|
||||
# On llm.kis.gov.lv server
|
||||
cd /opt/kisc-llm/poc/deploy
|
||||
|
||||
# Extract private key from keypair-SECURE.json
|
||||
PRIVATE_KEY_PEM=$(cat /path/to/keypair-SECURE.json | jq -r '.private_key_pem')
|
||||
|
||||
# Add to .env (replace newlines with \n)
|
||||
echo "MCPF_PRIVATE_KEY=\"$PRIVATE_KEY_PEM\"" >> .env
|
||||
|
||||
# Verify (should show -----BEGIN PRIVATE KEY-----)
|
||||
grep MCPF_PRIVATE_KEY .env | head -c 100
|
||||
|
||||
# Secure the .env file
|
||||
chmod 600 .env
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
### Step 4: Update nginx Configuration
|
||||
|
||||
```bash
|
||||
# On llm.kis.gov.lv server
|
||||
cd /opt/kisc-llm/poc/deploy/nginx/conf.d
|
||||
|
||||
# Backup existing config
|
||||
cp default.conf default.conf.backup-$(date +%Y%m%d)
|
||||
|
||||
# Add .well-known location block (insert after line 30, before "location /")
|
||||
cat >> default.conf << 'EOF'
|
||||
|
||||
# ==========================================================================
|
||||
# MCPF .well-known endpoints
|
||||
# ==========================================================================
|
||||
location /.well-known/ {
|
||||
alias /opt/kisc-llm/poc/deploy/.well-known/;
|
||||
|
||||
# CORS headers for trust framework discovery
|
||||
add_header Access-Control-Allow-Origin * always;
|
||||
add_header Access-Control-Allow-Methods "GET, OPTIONS" always;
|
||||
add_header Access-Control-Allow-Headers "Content-Type" always;
|
||||
|
||||
# Cache DID documents for 1 hour (they rarely change)
|
||||
add_header Cache-Control "public, max-age=3600" always;
|
||||
|
||||
# Serve JSON files
|
||||
location ~ \.(json)$ {
|
||||
add_header Content-Type application/json;
|
||||
}
|
||||
|
||||
# Serve text files
|
||||
location ~ \.(txt)$ {
|
||||
add_header Content-Type text/plain;
|
||||
}
|
||||
|
||||
# No directory listing
|
||||
autoindex off;
|
||||
}
|
||||
|
||||
EOF
|
||||
|
||||
# Validate nginx config
|
||||
docker exec kisc-nginx nginx -t
|
||||
|
||||
# If validation passes, reload
|
||||
docker exec kisc-nginx nginx -s reload
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
### Step 5: Update start.sh Script
|
||||
|
||||
Add MCPF integration steps to `/opt/kisc-llm/poc/deploy/scripts/start.sh`:
|
||||
|
||||
```bash
|
||||
# Insert after Step 3 (TLS cert handling), before Step 4 (OpenGateLLM start)
|
||||
|
||||
# =============================================================================
|
||||
# Step 3.5: MCPF .well-known Files
|
||||
# =============================================================================
|
||||
log_step "Step 3.5: Checking MCPF .well-known files..."
|
||||
|
||||
if [[ ! -f "$DEPLOY_DIR/.well-known/did.json" ]]; then
|
||||
log_error "MCPF .well-known files not found!"
|
||||
log_error "Run: rsync -av /path/to/wellknown/ $DEPLOY_DIR/.well-known/"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# Verify critical files exist
|
||||
REQUIRED_FILES=(
|
||||
".well-known/did.json"
|
||||
".well-known/jwks.json"
|
||||
".well-known/mcp-trust-registry.json"
|
||||
".well-known/mcp/manifest.json"
|
||||
".well-known/credentials/mcp-server.json"
|
||||
)
|
||||
|
||||
for file in "${REQUIRED_FILES[@]}"; do
|
||||
if [[ ! -f "$DEPLOY_DIR/$file" ]]; then
|
||||
log_warn "Missing: $file"
|
||||
fi
|
||||
done
|
||||
|
||||
log_info "MCPF .well-known files OK"
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
### Step 6: Update status.sh Script
|
||||
|
||||
Add MCPF health checks to `/opt/kisc-llm/poc/deploy/scripts/status.sh`:
|
||||
|
||||
```bash
|
||||
# Insert at the end, before final completion message
|
||||
|
||||
# =============================================================================
|
||||
# MCPF ENDPOINTS STATUS
|
||||
# =============================================================================
|
||||
echo -e "${CYAN}MCPF Endpoints:${NC}"
|
||||
echo "----------------------------------------"
|
||||
|
||||
check_wellknown() {
|
||||
local endpoint=$1
|
||||
local name=$2
|
||||
local response
|
||||
response=$(curl -sS -k --connect-timeout 2 "https://localhost$endpoint" 2>/dev/null || echo "")
|
||||
|
||||
if [[ -n "$response" ]] && echo "$response" | grep -q "@context\|keys\|mcpfVersion"; then
|
||||
echo -e " ${GREEN}✅${NC} $name"
|
||||
else
|
||||
echo -e " ${RED}❌${NC} $name (HTTP error or empty response)"
|
||||
fi
|
||||
}
|
||||
|
||||
check_wellknown "/.well-known/did.json" "DID Document"
|
||||
check_wellknown "/.well-known/jwks.json" "JWKS"
|
||||
check_wellknown "/.well-known/mcp-trust-registry.json" "MCPF Registry Discovery"
|
||||
check_wellknown "/.well-known/mcp/manifest.json" "MCP Manifest"
|
||||
check_wellknown "/.well-known/credentials/mcp-server.json" "MCP Credential"
|
||||
|
||||
echo ""
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
### Step 7: Validate Deployment
|
||||
|
||||
```bash
|
||||
# On llm.kis.gov.lv server
|
||||
cd /opt/kisc-llm/poc/deploy
|
||||
|
||||
# Test .well-known endpoints
|
||||
./scripts/validate-endpoints.sh
|
||||
|
||||
# Expected output:
|
||||
# ✅ DID Document: https://llm.kis.gov.lv/.well-known/did.json
|
||||
# ✅ JWKS: https://llm.kis.gov.lv/.well-known/jwks.json
|
||||
# ✅ MCPF Registry: https://llm.kis.gov.lv/.well-known/mcp-trust-registry.json
|
||||
# ✅ MCP Manifest: https://llm.kis.gov.lv/.well-known/mcp/manifest.json
|
||||
# ✅ MCP Credential: https://llm.kis.gov.lv/.well-known/credentials/mcp-server.json
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## Part B: VeriTrust Integration
|
||||
|
||||
### Step 8: Submit to VeriTrust for Credential Issuance
|
||||
|
||||
**KISC already has a VeriTrust profile!**
|
||||
|
||||
Existing KISC DID in VeriTrust:
|
||||
- `did:key:z6Mkuwv1z6y2yorbBf4LEkNzJCg16ERVfWE3bJEPKXtQm7a9` (Holder DID)
|
||||
- `did:web:veritrust.vc:portal:company:df0684bd-b54a-4684-b3d6-93a3b1c4bcb9` (Public Alias)
|
||||
|
||||
**Action Required:**
|
||||
|
||||
1. **Contact VeriTrust** via existing relationship
|
||||
2. **Request MCPServerCredential** for `did:web:llm.kis.gov.lv`
|
||||
3. **Provide:**
|
||||
- DID: `did:web:llm.kis.gov.lv`
|
||||
- Public Key (multibase): `z6MkjWGNnJsdyvutfbsytFJhkwDwyHkMkfWVL8X1fS1yBm2w`
|
||||
- MCP Endpoint: `https://llm.kis.gov.lv/mcp`
|
||||
- Manifest URL: `https://llm.kis.gov.lv/.well-known/mcp/manifest.json`
|
||||
- Organization: KISC (Kultūras informācijas sistēmu centrs)
|
||||
- Owner: Kultūras ministrija
|
||||
- Compliance: GDPR, NIS2, Latvian Data Protection Act
|
||||
|
||||
**Submission Payload:** See `veritrust/mcp-server-request.json`
|
||||
|
||||
---
|
||||
|
||||
### Step 9: Install VeriTrust-Issued Credential
|
||||
|
||||
Once VeriTrust issues the credential:
|
||||
|
||||
```bash
|
||||
# On llm.kis.gov.lv server
|
||||
cd /opt/kisc-llm/poc/deploy
|
||||
|
||||
# Backup placeholder
|
||||
cp .well-known/credentials/mcp-server.json .well-known/credentials/mcp-server.json.placeholder
|
||||
|
||||
# Install VeriTrust credential (replace PLACEHOLDER with actual credential)
|
||||
cat > .well-known/credentials/mcp-server.json << 'EOF'
|
||||
{
|
||||
"@context": [
|
||||
"https://www.w3.org/2018/credentials/v1",
|
||||
"https://mcpf.dev/credentials/v1"
|
||||
],
|
||||
"id": "https://llm.kis.gov.lv/.well-known/credentials/mcp-server.json",
|
||||
... (VeriTrust-provided credential JSON) ...
|
||||
}
|
||||
EOF
|
||||
|
||||
# Verify signature (use MCPF-python or manual verification)
|
||||
# The credential MUST be signed by did:web:veritrust.vc
|
||||
|
||||
# Reload nginx to pick up new credential
|
||||
docker exec kisc-nginx nginx -s reload
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## Validation & Testing
|
||||
|
||||
### Local Tests (from server)
|
||||
|
||||
```bash
|
||||
# Test DID Document
|
||||
curl https://llm.kis.gov.lv/.well-known/did.json | jq
|
||||
|
||||
# Test MCPF Registry Discovery
|
||||
curl https://llm.kis.gov.lv/.well-known/mcp-trust-registry.json | jq
|
||||
|
||||
# Test MCP Manifest
|
||||
curl https://llm.kis.gov.lv/.well-known/mcp/manifest.json | jq
|
||||
|
||||
# Test credential (placeholder until VeriTrust issues)
|
||||
curl https://llm.kis.gov.lv/.well-known/credentials/mcp-server.json | jq
|
||||
```
|
||||
|
||||
### External Tests (from any machine)
|
||||
|
||||
```bash
|
||||
# DID Resolution (W3C standard)
|
||||
curl https://llm.kis.gov.lv/.well-known/did.json
|
||||
|
||||
# Should return:
|
||||
# {
|
||||
# "@context": [...],
|
||||
# "id": "did:web:llm.kis.gov.lv",
|
||||
# "verificationMethod": [...],
|
||||
# ...
|
||||
# }
|
||||
```
|
||||
|
||||
### AI Agent Discovery Test
|
||||
|
||||
```python
|
||||
import requests
|
||||
|
||||
# Agent discovers MCPF-enabled MCP server
|
||||
registry_response = requests.get("https://llm.kis.gov.lv/.well-known/mcp-trust-registry.json")
|
||||
print(registry_response.json())
|
||||
|
||||
# Agent fetches credential for verification
|
||||
credential_url = registry_response.json()["services"]["mcp"]["credential"]
|
||||
credential = requests.get(credential_url).json()
|
||||
|
||||
# Agent verifies signature against did:web:veritrust.vc
|
||||
# (Use MCPF-python for full verification)
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## Troubleshooting
|
||||
|
||||
### Issue: 404 on .well-known endpoints
|
||||
|
||||
**Cause:** nginx not serving .well-known directory
|
||||
|
||||
**Fix:**
|
||||
```bash
|
||||
# Check nginx volume mount
|
||||
docker inspect kisc-nginx | grep .well-known
|
||||
|
||||
# If missing, update docker-compose.yml:
|
||||
volumes:
|
||||
- ./.well-known:/opt/kisc-llm/poc/deploy/.well-known:ro
|
||||
|
||||
# Restart
|
||||
docker restart kisc-nginx
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
### Issue: CORS errors when agents try to fetch DID
|
||||
|
||||
**Cause:** Missing CORS headers
|
||||
|
||||
**Fix:** Ensure nginx config has:
|
||||
```nginx
|
||||
add_header Access-Control-Allow-Origin * always;
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
### Issue: Private key not found in .env
|
||||
|
||||
**Cause:** MCPF_PRIVATE_KEY not set
|
||||
|
||||
**Fix:**
|
||||
```bash
|
||||
# Check .env
|
||||
grep MCPF_PRIVATE_KEY /opt/kisc-llm/poc/deploy/.env
|
||||
|
||||
# If missing, extract from keypair-SECURE.json and add
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## Security Checklist
|
||||
|
||||
Before going to production:
|
||||
|
||||
- [ ] `keypair-SECURE.json` deleted from server (only in `.env`)
|
||||
- [ ] `.env` has permissions `600` (read/write by owner only)
|
||||
- [ ] `.well-known` files have permissions `644` (world-readable)
|
||||
- [ ] Private key backed up offline (encrypted)
|
||||
- [ ] Access control documented (who has private key)
|
||||
- [ ] VeriTrust credential installed (not placeholder)
|
||||
- [ ] All endpoints accessible via HTTPS only
|
||||
- [ ] nginx TLS configured correctly (Let's Encrypt)
|
||||
|
||||
---
|
||||
|
||||
## Next Steps
|
||||
|
||||
1. **Deploy locally** (Part A) — Complete Steps 1-7
|
||||
2. **Submit to VeriTrust** (Part B) — Step 8
|
||||
3. **Install credential** — Step 9 (after VeriTrust response)
|
||||
4. **Test with AI agents** — Validate MCPF discovery workflow
|
||||
5. **Monitor** — Check logs, status.sh output
|
||||
6. **Document** — Update KISC internal documentation
|
||||
|
||||
---
|
||||
|
||||
## Support
|
||||
|
||||
- **MCPF Specification:** https://github.com/MCPTrustFramework/MCPF-specification
|
||||
- **VeriTrust:** https://veritrust.vc
|
||||
- **Questions:** Contact Rihards (Veritrust relationship) or KISC IT team
|
||||
|
||||
---
|
||||
|
||||
**Version:** 1.0
|
||||
**Last Updated:** 2026-01-30
|
||||
**Status:** Ready for Deployment
|
||||
@@ -0,0 +1,138 @@
|
||||
#!/usr/bin/env bash
|
||||
###############################################################################
|
||||
# KISC MCPF - Validate .well-known Endpoints
|
||||
#
|
||||
# Tests all MCPF endpoints are accessible and return valid JSON
|
||||
#
|
||||
# Usage: ./validate-endpoints.sh [domain]
|
||||
# Default domain: localhost (for local testing)
|
||||
# Production: ./validate-endpoints.sh llm.kis.gov.lv
|
||||
###############################################################################
|
||||
set -euo pipefail
|
||||
|
||||
DOMAIN="${1:-localhost}"
|
||||
BASE_URL="https://$DOMAIN"
|
||||
|
||||
# Use -k for localhost self-signed certs
|
||||
CURL_OPTS="-sS --connect-timeout 5 --max-time 10"
|
||||
if [[ "$DOMAIN" == "localhost" ]]; then
|
||||
CURL_OPTS="$CURL_OPTS -k"
|
||||
fi
|
||||
|
||||
# Colors
|
||||
GREEN='\033[0;32m'
|
||||
RED='\033[0;31m'
|
||||
YELLOW='\033[1;33m'
|
||||
NC='\033[0m'
|
||||
|
||||
PASSED=0
|
||||
FAILED=0
|
||||
|
||||
echo "============================================"
|
||||
echo "MCPF Endpoint Validation"
|
||||
echo "============================================"
|
||||
echo "Target: $BASE_URL"
|
||||
echo ""
|
||||
|
||||
test_endpoint() {
|
||||
local path=$1
|
||||
local name=$2
|
||||
local required_field=$3
|
||||
|
||||
echo -n "Testing $name... "
|
||||
|
||||
local url="$BASE_URL$path"
|
||||
local response
|
||||
response=$(curl $CURL_OPTS "$url" 2>/dev/null || echo "")
|
||||
|
||||
if [[ -z "$response" ]]; then
|
||||
echo -e "${RED}❌ FAIL${NC} (No response)"
|
||||
echo " URL: $url"
|
||||
((FAILED++))
|
||||
return 1
|
||||
fi
|
||||
|
||||
# Check if valid JSON
|
||||
if ! echo "$response" | jq empty 2>/dev/null; then
|
||||
echo -e "${RED}❌ FAIL${NC} (Invalid JSON)"
|
||||
echo " URL: $url"
|
||||
echo " Response: ${response:0:100}..."
|
||||
((FAILED++))
|
||||
return 1
|
||||
fi
|
||||
|
||||
# Check for required field
|
||||
if [[ -n "$required_field" ]]; then
|
||||
if ! echo "$response" | jq -e "$required_field" >/dev/null 2>&1; then
|
||||
echo -e "${YELLOW}⚠️ WARN${NC} (Missing field: $required_field)"
|
||||
echo " URL: $url"
|
||||
fi
|
||||
fi
|
||||
|
||||
echo -e "${GREEN}✅ PASS${NC}"
|
||||
echo " URL: $url"
|
||||
((PASSED++))
|
||||
}
|
||||
|
||||
# =============================================================================
|
||||
# Test Suite
|
||||
# =============================================================================
|
||||
|
||||
# Test 1: DID Document
|
||||
test_endpoint "/.well-known/did.json" "DID Document" ".id"
|
||||
|
||||
# Test 2: JWKS
|
||||
test_endpoint "/.well-known/jwks.json" "JWKS" ".keys"
|
||||
|
||||
# Test 3: MCPF Registry Discovery
|
||||
test_endpoint "/.well-known/mcp-trust-registry.json" "MCPF Registry Discovery" ".mcpfVersion"
|
||||
|
||||
# Test 4: Security.txt
|
||||
echo -n "Testing Security.txt... "
|
||||
response=$(curl $CURL_OPTS "$BASE_URL/.well-known/security.txt" 2>/dev/null || echo "")
|
||||
if echo "$response" | grep -q "Contact:"; then
|
||||
echo -e "${GREEN}✅ PASS${NC}"
|
||||
echo " URL: $BASE_URL/.well-known/security.txt"
|
||||
((PASSED++))
|
||||
else
|
||||
echo -e "${RED}❌ FAIL${NC}"
|
||||
((FAILED++))
|
||||
fi
|
||||
|
||||
# Test 5: MCP Manifest
|
||||
test_endpoint "/.well-known/mcp/manifest.json" "MCP Manifest" ".capabilities"
|
||||
|
||||
# Test 6: MCP Credential
|
||||
test_endpoint "/.well-known/credentials/mcp-server.json" "MCP Credential" ".credentialSubject"
|
||||
|
||||
# =============================================================================
|
||||
# Results
|
||||
# =============================================================================
|
||||
|
||||
echo ""
|
||||
echo "============================================"
|
||||
echo "Results"
|
||||
echo "============================================"
|
||||
echo "Passed: $PASSED"
|
||||
echo "Failed: $FAILED"
|
||||
echo ""
|
||||
|
||||
if [[ $FAILED -eq 0 ]]; then
|
||||
echo -e "${GREEN}✅ All tests passed!${NC}"
|
||||
echo ""
|
||||
echo "MCPF integration is working correctly."
|
||||
echo "Next steps:"
|
||||
echo " 1. Submit to VeriTrust for credential issuance"
|
||||
echo " 2. Replace placeholder credential in /.well-known/credentials/mcp-server.json"
|
||||
echo " 3. Test with AI agents (Claude Desktop, ChatGPT, etc.)"
|
||||
exit 0
|
||||
else
|
||||
echo -e "${RED}❌ Some tests failed${NC}"
|
||||
echo ""
|
||||
echo "Troubleshooting:"
|
||||
echo " 1. Check nginx is serving .well-known directory"
|
||||
echo " 2. Verify .well-known files exist in /opt/kisc-llm/poc/deploy/.well-known/"
|
||||
echo " 3. Check nginx logs: docker logs kisc-nginx"
|
||||
echo " 4. Verify TLS certificates are valid"
|
||||
exit 1
|
||||
fi
|
||||
@@ -0,0 +1,247 @@
|
||||
# VeriTrust MCPF Credential Submission
|
||||
|
||||
## Overview
|
||||
|
||||
KISC already has a VeriTrust organization profile. This submission requests a **MCPServerCredential** for the new `did:web:llm.kis.gov.lv` identity.
|
||||
|
||||
---
|
||||
|
||||
## Existing KISC Profile in VeriTrust
|
||||
|
||||
**Holder DID:** `did:key:z6Mkuwv1z6y2yorbBf4LEkNzJCg16ERVfWE3bJEPKXtQm7a9`
|
||||
**Public Alias:** `did:web:veritrust.vc:portal:company:df0684bd-b54a-4684-b3d6-93a3b1c4bcb9`
|
||||
**Status:** Verified
|
||||
|
||||
---
|
||||
|
||||
## New Identity for MCP Server
|
||||
|
||||
**DID:** `did:web:llm.kis.gov.lv`
|
||||
**Public Key (multibase):** `z6MkjWGNnJsdyvutfbsytFJhkwDwyHkMkfWVL8X1fS1yBm2w`
|
||||
**Service Endpoint:** `https://llm.kis.gov.lv/mcp`
|
||||
**Manifest:** `https://llm.kis.gov.lv/.well-known/mcp/manifest.json`
|
||||
|
||||
---
|
||||
|
||||
## Submission Process
|
||||
|
||||
### Step 1: Verify Local Deployment
|
||||
|
||||
Before submitting to VeriTrust, ensure:
|
||||
|
||||
```bash
|
||||
# All .well-known endpoints accessible
|
||||
curl https://llm.kis.gov.lv/.well-known/did.json
|
||||
curl https://llm.kis.gov.lv/.well-known/mcp-trust-registry.json
|
||||
curl https://llm.kis.gov.lv/.well-known/mcp/manifest.json
|
||||
|
||||
# MCP server operational
|
||||
curl https://llm.kis.gov.lv/mcp-health
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
### Step 2: Submit Credential Request
|
||||
|
||||
**Method 1: Via VeriTrust Portal (Recommended)**
|
||||
|
||||
1. Log into VeriTrust portal: https://veritrust.vc/portal
|
||||
2. Navigate to your KISC organization profile
|
||||
3. Click "Request Credential" → "MCP Server Credential"
|
||||
4. Fill in form with data from `mcp-server-request.json`
|
||||
5. Upload or paste:
|
||||
- DID: `did:web:llm.kis.gov.lv`
|
||||
- Public key (multibase): `z6MkjWGNnJsdyvutfbsytFJhkwDwyHkMkfWVL8X1fS1yBm2w`
|
||||
- Endpoint: `https://llm.kis.gov.lv/mcp`
|
||||
- Manifest URL: `https://llm.kis.gov.lv/.well-known/mcp/manifest.json`
|
||||
6. Submit for review
|
||||
|
||||
**Method 2: Via API (If Available)**
|
||||
|
||||
```bash
|
||||
# POST to VeriTrust credential issuance API
|
||||
curl -X POST https://veritrust.vc/api/v1/credentials/issue \
|
||||
-H "Authorization: Bearer $VERITRUST_API_KEY" \
|
||||
-H "Content-Type: application/json" \
|
||||
-d @mcp-server-request.json
|
||||
```
|
||||
|
||||
**Method 3: Email Submission**
|
||||
|
||||
Send `mcp-server-request.json` to: credentials@veritrust.vc
|
||||
|
||||
Include:
|
||||
- Subject: "KISC MCP Server Credential Request - did:web:llm.kis.gov.lv"
|
||||
- Body: Reference existing KISC profile (did:key:z6Mkuwv1z6y2yorbBf4LEkNzJCg16ERVfWE3bJEPKXtQm7a9)
|
||||
- Attach: mcp-server-request.json
|
||||
|
||||
---
|
||||
|
||||
### Step 3: Verification by VeriTrust
|
||||
|
||||
VeriTrust will verify:
|
||||
|
||||
1. ✅ KISC organization profile exists and is verified
|
||||
2. ✅ `llm.kis.gov.lv` domain is controlled by KISC
|
||||
3. ✅ DID document accessible at `https://llm.kis.gov.lv/.well-known/did.json`
|
||||
4. ✅ MCP manifest valid at `https://llm.kis.gov.lv/.well-known/mcp/manifest.json`
|
||||
5. ✅ Public key matches DID document
|
||||
6. ✅ Compliance claims are accurate (GDPR, NIS2)
|
||||
|
||||
**Timeline:** 1-5 business days (typically 1-2 days for verified organizations)
|
||||
|
||||
---
|
||||
|
||||
### Step 4: Receive Credential
|
||||
|
||||
VeriTrust will provide:
|
||||
|
||||
```json
|
||||
{
|
||||
"@context": [
|
||||
"https://www.w3.org/2018/credentials/v1",
|
||||
"https://mcpf.dev/credentials/v1"
|
||||
],
|
||||
"id": "https://veritrust.vc/credentials/[UUID]",
|
||||
"type": ["VerifiableCredential", "MCPServerCredential"],
|
||||
"issuer": {
|
||||
"id": "did:web:veritrust.vc",
|
||||
"name": "VeriTrust"
|
||||
},
|
||||
"issuanceDate": "2026-01-30T10:00:00Z",
|
||||
"expirationDate": "2027-01-30T10:00:00Z",
|
||||
"credentialSubject": {
|
||||
"id": "did:web:llm.kis.gov.lv#mcp-server",
|
||||
...
|
||||
},
|
||||
"credentialStatus": {
|
||||
"id": "https://veritrust.vc/status/2026#94567",
|
||||
"type": "StatusList2021Entry",
|
||||
...
|
||||
},
|
||||
"proof": {
|
||||
"type": "Ed25519Signature2020",
|
||||
"created": "2026-01-30T10:00:00Z",
|
||||
"verificationMethod": "did:web:veritrust.vc#key-1",
|
||||
"proofPurpose": "assertionMethod",
|
||||
"proofValue": "z5vgK8B..." // VeriTrust's cryptographic signature
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
### Step 5: Install Credential
|
||||
|
||||
Use the provided `install-credential.sh` script:
|
||||
|
||||
```bash
|
||||
# On llm.kis.gov.lv server
|
||||
cd /opt/kisc-llm/poc/deploy
|
||||
|
||||
# Save VeriTrust credential to temporary file
|
||||
cat > /tmp/veritrust-credential.json << 'EOF'
|
||||
{
|
||||
... (paste VeriTrust-provided credential JSON) ...
|
||||
}
|
||||
EOF
|
||||
|
||||
# Run install script
|
||||
./veritrust/install-credential.sh /tmp/veritrust-credential.json
|
||||
|
||||
# Verify installation
|
||||
curl https://llm.kis.gov.lv/.well-known/credentials/mcp-server.json | jq
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
### Step 6: Register in MCPF Registry
|
||||
|
||||
VeriTrust will automatically register the MCP server in their MCPF registry at `https://mcp.veritrust.vc`.
|
||||
|
||||
Verify registration:
|
||||
|
||||
```bash
|
||||
# Search by country
|
||||
curl "https://mcp.veritrust.vc/mcp/search?country=LV"
|
||||
|
||||
# Get specific server
|
||||
curl "https://mcp.veritrust.vc/mcp/servers/did:web:llm.kis.gov.lv"
|
||||
```
|
||||
|
||||
Expected response:
|
||||
```json
|
||||
{
|
||||
"did": "did:web:llm.kis.gov.lv",
|
||||
"endpoint": "https://llm.kis.gov.lv/mcp",
|
||||
"manifest": "https://llm.kis.gov.lv/.well-known/mcp/manifest.json",
|
||||
"credentials": [
|
||||
"https://llm.kis.gov.lv/.well-known/credentials/mcp-server.json"
|
||||
],
|
||||
"metadata": {
|
||||
"organization": "Kultūras informācijas sistēmu centrs",
|
||||
"country": "LV",
|
||||
"tags": ["architecture", "government", "latvia", "culture"],
|
||||
"status": "active"
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## Troubleshooting
|
||||
|
||||
### VeriTrust cannot verify domain ownership
|
||||
|
||||
**Solution:** Add DNS TXT record:
|
||||
|
||||
```
|
||||
_veritrust.llm.kis.gov.lv TXT "did=did:web:llm.kis.gov.lv"
|
||||
```
|
||||
|
||||
### VeriTrust cannot fetch DID document
|
||||
|
||||
**Solution:** Verify HTTPS and CORS:
|
||||
|
||||
```bash
|
||||
curl -I https://llm.kis.gov.lv/.well-known/did.json
|
||||
# Should show:
|
||||
# HTTP/2 200
|
||||
# access-control-allow-origin: *
|
||||
# content-type: application/json
|
||||
```
|
||||
|
||||
### Credential issuance delayed
|
||||
|
||||
**Solution:** Contact VeriTrust support with:
|
||||
- Organization: KISC
|
||||
- Existing DID: did:key:z6Mkuwv1z6y2yorbBf4LEkNzJCg16ERVfWE3bJEPKXtQm7a9
|
||||
- New DID: did:web:llm.kis.gov.lv
|
||||
- Request ID: (if provided)
|
||||
|
||||
---
|
||||
|
||||
## Contact
|
||||
|
||||
**VeriTrust Support:**
|
||||
- Website: https://veritrust.vc
|
||||
- Email: support@veritrust.vc (or credentials@veritrust.vc)
|
||||
- Portal: https://veritrust.vc/portal
|
||||
|
||||
**KISC Contact:**
|
||||
- Rihards (VeriTrust relationship)
|
||||
- KISC IT operations team
|
||||
|
||||
---
|
||||
|
||||
## Credential Renewal
|
||||
|
||||
**Expiration:** 1 year from issuance
|
||||
**Renewal Process:** 30 days before expiration, VeriTrust will notify KISC via email
|
||||
**Action Required:** Confirm renewal (usually automatic for verified organizations)
|
||||
|
||||
---
|
||||
|
||||
**Version:** 1.0
|
||||
**Last Updated:** 2026-01-30
|
||||
**Status:** Ready for Submission
|
||||
@@ -0,0 +1,206 @@
|
||||
#!/usr/bin/env bash
|
||||
###############################################################################
|
||||
# KISC MCPF - Install VeriTrust-Issued Credential
|
||||
#
|
||||
# Installs the VeriTrust-signed MCP Server Credential and validates it
|
||||
#
|
||||
# Usage: ./install-credential.sh <credential-file.json>
|
||||
###############################################################################
|
||||
set -euo pipefail
|
||||
|
||||
CREDENTIAL_FILE="${1:-}"
|
||||
DEPLOY_DIR="/opt/kisc-llm/poc/deploy"
|
||||
TARGET="$DEPLOY_DIR/.well-known/credentials/mcp-server.json"
|
||||
|
||||
# Colors
|
||||
GREEN='\033[0;32m'
|
||||
RED='\033[0;31m'
|
||||
YELLOW='\033[1;33m'
|
||||
NC='\033[0m'
|
||||
|
||||
log_info() { echo -e "${GREEN}[INFO]${NC} $1"; }
|
||||
log_warn() { echo -e "${YELLOW}[WARN]${NC} $1"; }
|
||||
log_error() { echo -e "${RED}[ERROR]${NC} $1"; }
|
||||
|
||||
# =============================================================================
|
||||
# Validation
|
||||
# =============================================================================
|
||||
|
||||
if [[ -z "$CREDENTIAL_FILE" ]]; then
|
||||
log_error "Usage: $0 <credential-file.json>"
|
||||
echo ""
|
||||
echo "Example:"
|
||||
echo " $0 /tmp/veritrust-credential.json"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
if [[ ! -f "$CREDENTIAL_FILE" ]]; then
|
||||
log_error "File not found: $CREDENTIAL_FILE"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
if [[ ! -d "$DEPLOY_DIR" ]]; then
|
||||
log_error "Deploy directory not found: $DEPLOY_DIR"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
echo "============================================"
|
||||
echo "Install VeriTrust Credential"
|
||||
echo "============================================"
|
||||
echo "Source: $CREDENTIAL_FILE"
|
||||
echo "Target: $TARGET"
|
||||
echo ""
|
||||
|
||||
# =============================================================================
|
||||
# Validate Credential Format
|
||||
# =============================================================================
|
||||
|
||||
log_info "Step 1: Validating credential format..."
|
||||
|
||||
# Check if valid JSON
|
||||
if ! jq empty "$CREDENTIAL_FILE" 2>/dev/null; then
|
||||
log_error "Invalid JSON in credential file"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# Check required fields
|
||||
REQUIRED_FIELDS=(
|
||||
"@context"
|
||||
"type"
|
||||
"issuer.id"
|
||||
"credentialSubject.id"
|
||||
"proof.type"
|
||||
"proof.proofValue"
|
||||
)
|
||||
|
||||
for field in "${REQUIRED_FIELDS[@]}"; do
|
||||
if ! jq -e ".$field" "$CREDENTIAL_FILE" >/dev/null 2>&1; then
|
||||
log_error "Missing required field: $field"
|
||||
exit 1
|
||||
fi
|
||||
done
|
||||
|
||||
# Verify issuer is VeriTrust
|
||||
ISSUER=$(jq -r '.issuer.id' "$CREDENTIAL_FILE")
|
||||
if [[ "$ISSUER" != "did:web:veritrust.vc" ]]; then
|
||||
log_error "Invalid issuer: $ISSUER (expected: did:web:veritrust.vc)"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# Verify subject is KISC MCP server
|
||||
SUBJECT=$(jq -r '.credentialSubject.id' "$CREDENTIAL_FILE")
|
||||
if [[ "$SUBJECT" != "did:web:llm.kis.gov.lv#mcp-server" ]]; then
|
||||
log_warn "Subject mismatch: $SUBJECT (expected: did:web:llm.kis.gov.lv#mcp-server)"
|
||||
fi
|
||||
|
||||
# Check expiration
|
||||
EXPIRATION=$(jq -r '.expirationDate' "$CREDENTIAL_FILE")
|
||||
log_info "Credential expires: $EXPIRATION"
|
||||
|
||||
log_info "✅ Credential format valid"
|
||||
echo ""
|
||||
|
||||
# =============================================================================
|
||||
# Backup Existing Credential
|
||||
# =============================================================================
|
||||
|
||||
log_info "Step 2: Backing up existing credential..."
|
||||
|
||||
if [[ -f "$TARGET" ]]; then
|
||||
BACKUP="$TARGET.backup-$(date +%Y%m%d-%H%M%S)"
|
||||
cp "$TARGET" "$BACKUP"
|
||||
log_info "Backup created: $BACKUP"
|
||||
else
|
||||
log_warn "No existing credential to backup"
|
||||
fi
|
||||
|
||||
echo ""
|
||||
|
||||
# =============================================================================
|
||||
# Install New Credential
|
||||
# =============================================================================
|
||||
|
||||
log_info "Step 3: Installing new credential..."
|
||||
|
||||
# Copy credential to target location
|
||||
cp "$CREDENTIAL_FILE" "$TARGET"
|
||||
|
||||
# Set permissions (world-readable)
|
||||
chmod 644 "$TARGET"
|
||||
|
||||
log_info "✅ Credential installed: $TARGET"
|
||||
echo ""
|
||||
|
||||
# =============================================================================
|
||||
# Reload nginx
|
||||
# =============================================================================
|
||||
|
||||
log_info "Step 4: Reloading nginx..."
|
||||
|
||||
if docker ps --format '{{.Names}}' | grep -q "kisc-nginx"; then
|
||||
docker exec kisc-nginx nginx -s reload
|
||||
log_info "✅ nginx reloaded"
|
||||
else
|
||||
log_warn "nginx container not found, skipping reload"
|
||||
fi
|
||||
|
||||
echo ""
|
||||
|
||||
# =============================================================================
|
||||
# Verify Installation
|
||||
# =============================================================================
|
||||
|
||||
log_info "Step 5: Verifying installation..."
|
||||
|
||||
# Test endpoint
|
||||
RESPONSE=$(curl -sS -k https://localhost/.well-known/credentials/mcp-server.json 2>/dev/null || echo "")
|
||||
|
||||
if [[ -z "$RESPONSE" ]]; then
|
||||
log_error "Endpoint not accessible"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
if ! echo "$RESPONSE" | jq empty 2>/dev/null; then
|
||||
log_error "Endpoint returned invalid JSON"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# Check proof value matches
|
||||
INSTALLED_PROOF=$(echo "$RESPONSE" | jq -r '.proof.proofValue')
|
||||
SOURCE_PROOF=$(jq -r '.proof.proofValue' "$CREDENTIAL_FILE")
|
||||
|
||||
if [[ "$INSTALLED_PROOF" != "$SOURCE_PROOF" ]]; then
|
||||
log_error "Proof value mismatch! Installation may be corrupted."
|
||||
exit 1
|
||||
fi
|
||||
|
||||
log_info "✅ Installation verified"
|
||||
echo ""
|
||||
|
||||
# =============================================================================
|
||||
# Success Summary
|
||||
# =============================================================================
|
||||
|
||||
echo "============================================"
|
||||
echo "Installation Complete"
|
||||
echo "============================================"
|
||||
echo ""
|
||||
echo "Credential Details:"
|
||||
echo " Issuer: $(jq -r '.issuer.name' "$TARGET")"
|
||||
echo " Subject: $(jq -r '.credentialSubject.id' "$TARGET")"
|
||||
echo " Issued: $(jq -r '.issuanceDate' "$TARGET")"
|
||||
echo " Expires: $(jq -r '.expirationDate' "$TARGET")"
|
||||
echo " Status URL: $(jq -r '.credentialStatus.statusListCredential' "$TARGET")"
|
||||
echo ""
|
||||
echo "Endpoint:"
|
||||
echo " https://llm.kis.gov.lv/.well-known/credentials/mcp-server.json"
|
||||
echo ""
|
||||
echo "Next Steps:"
|
||||
echo " 1. Test external access:"
|
||||
echo " curl https://llm.kis.gov.lv/.well-known/credentials/mcp-server.json | jq"
|
||||
echo ""
|
||||
echo " 2. Verify in MCPF Registry:"
|
||||
echo " curl https://mcp.veritrust.vc/mcp/servers/did:web:llm.kis.gov.lv"
|
||||
echo ""
|
||||
echo " 3. Test with AI agent (Claude Desktop, ChatGPT, etc.)"
|
||||
echo ""
|
||||
@@ -0,0 +1,66 @@
|
||||
{
|
||||
"credentialType": "MCPServerCredential",
|
||||
"subject": {
|
||||
"did": "did:web:llm.kis.gov.lv",
|
||||
"type": "MCPServer",
|
||||
"endpoint": "https://llm.kis.gov.lv/mcp",
|
||||
"manifest": "https://llm.kis.gov.lv/.well-known/mcp/manifest.json"
|
||||
},
|
||||
"controller": {
|
||||
"id": "org.kisc",
|
||||
"name": "Kultūras informācijas sistēmu centrs",
|
||||
"registrationNumber": "KISC-REG-NUMBER",
|
||||
"country": "LV",
|
||||
"website": "https://kis.gov.lv",
|
||||
"existingDID": "did:key:z6Mkuwv1z6y2yorbBf4LEkNzJCg16ERVfWE3bJEPKXtQm7a9"
|
||||
},
|
||||
"owner": {
|
||||
"id": "org.km",
|
||||
"name": "Kultūras ministrija",
|
||||
"country": "LV",
|
||||
"website": "https://km.gov.lv"
|
||||
},
|
||||
"capabilities": [
|
||||
{
|
||||
"name": "search",
|
||||
"description": "Search YAML registers and Markdown documentation",
|
||||
"riskLevel": "low"
|
||||
},
|
||||
{
|
||||
"name": "get_entity",
|
||||
"description": "Retrieve entity by canonical ID",
|
||||
"riskLevel": "low"
|
||||
}
|
||||
],
|
||||
"governance": {
|
||||
"assuranceLevel": "substantial",
|
||||
"compliance": [
|
||||
"GDPR",
|
||||
"NIS2",
|
||||
"Latvian-Data-Protection-Act"
|
||||
],
|
||||
"dataClassification": "public",
|
||||
"certifications": [],
|
||||
"auditTrail": true
|
||||
},
|
||||
"publicKey": {
|
||||
"type": "Ed25519VerificationKey2020",
|
||||
"multibase": "z6MkjWGNnJsdyvutfbsytFJhkwDwyHkMkfWVL8X1fS1yBm2w",
|
||||
"jwk": {
|
||||
"kty": "OKP",
|
||||
"crv": "Ed25519",
|
||||
"x": "Sw-NGiVKSYj0zsrL7ceP6EMV673IuL2bYzHEypuojvA"
|
||||
}
|
||||
},
|
||||
"validityPeriod": {
|
||||
"notBefore": "2026-01-30T00:00:00Z",
|
||||
"notAfter": "2027-01-30T00:00:00Z"
|
||||
},
|
||||
"metadata": {
|
||||
"purpose": "MCPF Trust Framework integration for KISC MCP Server",
|
||||
"environment": "production",
|
||||
"poc": "POC-AI-LLM-1",
|
||||
"technicalContact": "support@kis.gov.lv",
|
||||
"requestDate": "2026-01-30"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,62 @@
|
||||
{
|
||||
"@context": [
|
||||
"https://www.w3.org/2018/credentials/v1",
|
||||
"https://mcpf.dev/credentials/v1"
|
||||
],
|
||||
"id": "https://llm.kis.gov.lv/.well-known/credentials/mcp-server.json",
|
||||
"type": [
|
||||
"VerifiableCredential",
|
||||
"MCPServerCredential"
|
||||
],
|
||||
"issuer": {
|
||||
"id": "did:web:veritrust.vc",
|
||||
"name": "VeriTrust"
|
||||
},
|
||||
"issuanceDate": "2026-01-30T00:00:00Z",
|
||||
"expirationDate": "2027-01-30T00:00:00Z",
|
||||
"credentialSubject": {
|
||||
"id": "did:web:llm.kis.gov.lv#mcp-server",
|
||||
"type": "MCPServer",
|
||||
"endpoint": "https://llm.kis.gov.lv/mcp",
|
||||
"manifest": "https://llm.kis.gov.lv/.well-known/mcp/manifest.json",
|
||||
"controller": {
|
||||
"id": "org.kisc",
|
||||
"name": "Kultūras informācijas sistēmu centrs",
|
||||
"country": "LV"
|
||||
},
|
||||
"owner": {
|
||||
"id": "org.km",
|
||||
"name": "Kultūras ministrija",
|
||||
"country": "LV"
|
||||
},
|
||||
"capabilities": [
|
||||
"search",
|
||||
"get_entity"
|
||||
],
|
||||
"governance": {
|
||||
"assuranceLevel": "substantial",
|
||||
"compliance": [
|
||||
"GDPR",
|
||||
"NIS2",
|
||||
"Latvian-Data-Protection-Act"
|
||||
],
|
||||
"dataClassification": "public",
|
||||
"certifications": []
|
||||
}
|
||||
},
|
||||
"credentialStatus": {
|
||||
"id": "https://veritrust.vc/status/2026#PLACEHOLDER",
|
||||
"type": "StatusList2021Entry",
|
||||
"statusPurpose": "revocation",
|
||||
"statusListIndex": "PLACEHOLDER",
|
||||
"statusListCredential": "https://veritrust.vc/status/2026"
|
||||
},
|
||||
"proof": {
|
||||
"type": "Ed25519Signature2020",
|
||||
"created": "2026-01-30T00:00:00Z",
|
||||
"verificationMethod": "did:web:veritrust.vc#key-1",
|
||||
"proofPurpose": "assertionMethod",
|
||||
"proofValue": "PLACEHOLDER_WILL_BE_REPLACED_BY_VERITRUST_SIGNATURE"
|
||||
},
|
||||
"_comment": "⚠️ PLACEHOLDER: This credential will be replaced by VeriTrust-issued credential. DO NOT use in production until replaced."
|
||||
}
|
||||
33
ikt-arh-kultura-valodu-tehnologijas/mcpf/wellknown/did.json
Normal file
33
ikt-arh-kultura-valodu-tehnologijas/mcpf/wellknown/did.json
Normal file
@@ -0,0 +1,33 @@
|
||||
{
|
||||
"@context": [
|
||||
"https://www.w3.org/ns/did/v1",
|
||||
"https://w3id.org/security/suites/ed25519-2020/v1"
|
||||
],
|
||||
"id": "did:web:llm.kis.gov.lv",
|
||||
"controller": "did:web:llm.kis.gov.lv",
|
||||
"verificationMethod": [
|
||||
{
|
||||
"id": "did:web:llm.kis.gov.lv#key-1",
|
||||
"type": "Ed25519VerificationKey2020",
|
||||
"controller": "did:web:llm.kis.gov.lv",
|
||||
"publicKeyMultibase": "z6MkjWGNnJsdyvutfbsytFJhkwDwyHkMkfWVL8X1fS1yBm2w"
|
||||
}
|
||||
],
|
||||
"authentication": [
|
||||
"did:web:llm.kis.gov.lv#key-1"
|
||||
],
|
||||
"assertionMethod": [
|
||||
"did:web:llm.kis.gov.lv#key-1"
|
||||
],
|
||||
"service": [
|
||||
{
|
||||
"id": "did:web:llm.kis.gov.lv#mcp-server",
|
||||
"type": "MCPServer",
|
||||
"serviceEndpoint": "https://llm.kis.gov.lv/mcp"
|
||||
}
|
||||
],
|
||||
"alsoKnownAs": [
|
||||
"https://llm.kis.gov.lv",
|
||||
"urn:kisc:llm-platform"
|
||||
]
|
||||
}
|
||||
12
ikt-arh-kultura-valodu-tehnologijas/mcpf/wellknown/jwks.json
Normal file
12
ikt-arh-kultura-valodu-tehnologijas/mcpf/wellknown/jwks.json
Normal file
@@ -0,0 +1,12 @@
|
||||
{
|
||||
"keys": [
|
||||
{
|
||||
"kty": "OKP",
|
||||
"crv": "Ed25519",
|
||||
"x": "Sw-NGiVKSYj0zsrL7ceP6EMV673IuL2bYzHEypuojvA",
|
||||
"use": "sig",
|
||||
"kid": "did:web:llm.kis.gov.lv#key-1",
|
||||
"alg": "EdDSA"
|
||||
}
|
||||
]
|
||||
}
|
||||
@@ -0,0 +1,18 @@
|
||||
{
|
||||
"@context": "https://mcpf.dev/registry/v1",
|
||||
"id": "did:web:llm.kis.gov.lv#trust-registry",
|
||||
"type": "MCPTrustRegistry",
|
||||
"version": "1.0",
|
||||
"publisher": {
|
||||
"id": "did:web:llm.kis.gov.lv",
|
||||
"name": "KISC - Kultūras informācijas sistēmu centrs"
|
||||
},
|
||||
"services": {
|
||||
"mcp": {
|
||||
"id": "did:web:llm.kis.gov.lv#mcp-server",
|
||||
"endpoint": "https://llm.kis.gov.lv/mcp",
|
||||
"manifest": "https://llm.kis.gov.lv/.well-known/mcp/manifest.json",
|
||||
"credential": "https://veritrust.vc/portal/mcp/credentials/aec9930b-9139-4b33-ac6f-ad3bd3d91da0.json"
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,135 @@
|
||||
{
|
||||
"@context": "https://modelcontextprotocol.io/schema/2025-03-26",
|
||||
"@type": "MCPServer",
|
||||
"id": "did:web:llm.kis.gov.lv#mcp-server",
|
||||
"name": "KISC MCP Server (IKT Architecture)",
|
||||
"version": "1.0.0",
|
||||
"description": "Target architecture for Latvian Cultural and Language Technology domain (Kultūras un valodas tehnoloģiju apakšjomas mērķarhitektūra)",
|
||||
"author": {
|
||||
"name": "Kultūras informācijas sistēmu centrs (KISC)",
|
||||
"url": "https://kis.gov.lv",
|
||||
"did": "did:web:llm.kis.gov.lv"
|
||||
},
|
||||
"capabilities": {
|
||||
"tools": true,
|
||||
"resources": false,
|
||||
"prompts": false,
|
||||
"sampling": false
|
||||
},
|
||||
"server": {
|
||||
"endpoint": "https://llm.kis.gov.lv/mcp",
|
||||
"transport": "sse",
|
||||
"authentication": {
|
||||
"required": false,
|
||||
"methods": []
|
||||
}
|
||||
},
|
||||
"tools": [
|
||||
{
|
||||
"name": "search",
|
||||
"description": "Search YAML registers and Markdown documentation across the target architecture",
|
||||
"inputSchema": {
|
||||
"type": "object",
|
||||
"properties": {
|
||||
"query": {
|
||||
"type": "string",
|
||||
"description": "Search query string (searches across all registers and views)"
|
||||
},
|
||||
"limit": {
|
||||
"type": "number",
|
||||
"description": "Maximum number of results to return",
|
||||
"default": 25,
|
||||
"maximum": 100
|
||||
}
|
||||
},
|
||||
"required": ["query"]
|
||||
}
|
||||
},
|
||||
{
|
||||
"name": "get_entity",
|
||||
"description": "Retrieve a specific entity by its canonical ID from the architecture registers",
|
||||
"inputSchema": {
|
||||
"type": "object",
|
||||
"properties": {
|
||||
"id": {
|
||||
"type": "string",
|
||||
"description": "Entity canonical ID (e.g., 'goal.m1', 'org.kisc', 'sys.kultura.01')",
|
||||
"pattern": "^[a-z]+\\.[a-z0-9_-]+$"
|
||||
}
|
||||
},
|
||||
"required": ["id"]
|
||||
}
|
||||
}
|
||||
],
|
||||
"mcpf": {
|
||||
"version": "0.1",
|
||||
"spec": {
|
||||
"repository": "https://github.com/MCPTrustFramework/MCPF-specification"
|
||||
},
|
||||
"entrypoint": {
|
||||
"type": "manifest",
|
||||
"url": "https://llm.kis.gov.lv/.well-known/mcp/manifest.json"
|
||||
},
|
||||
"artifacts": {
|
||||
"trust_registry": "https://llm.kis.gov.lv/.well-known/mcp-trust-registry.json",
|
||||
"credential": "https://veritrust.vc/portal/mcp/credentials/aec9930b-9139-4b33-ac6f-ad3bd3d91da0.json"
|
||||
}
|
||||
},
|
||||
"trust": {
|
||||
"verifications": [
|
||||
{
|
||||
"verifier": "did:web:veritrust.vc",
|
||||
"type": ["VerifiableCredential", "MCPServerVerification"],
|
||||
"credential": "https://veritrust.vc/portal/mcp/credentials/aec9930b-9139-4b33-ac6f-ad3bd3d91da0.json",
|
||||
"covers": "did:web:llm.kis.gov.lv",
|
||||
"proof_hint": {
|
||||
"verificationMethod": "did:web:veritrust.vc#key-1",
|
||||
"created": "2026-01-29T10:12:41Z"
|
||||
}
|
||||
}
|
||||
]
|
||||
},
|
||||
"metadata": {
|
||||
"organization": "Kultūras informācijas sistēmu centrs",
|
||||
"organizationType": "government",
|
||||
"country": "LV",
|
||||
"domain": "kultura-valoda",
|
||||
"tags": [
|
||||
"architecture",
|
||||
"government",
|
||||
"latvia",
|
||||
"culture",
|
||||
"language",
|
||||
"ikta",
|
||||
"enterprise-architecture",
|
||||
"target-architecture"
|
||||
],
|
||||
"dataClassification": "public",
|
||||
"compliance": [
|
||||
"GDPR",
|
||||
"NIS2",
|
||||
"Latvian-Data-Protection-Act"
|
||||
],
|
||||
"languages": [
|
||||
"lv",
|
||||
"en"
|
||||
],
|
||||
"status": "production"
|
||||
},
|
||||
"security": {
|
||||
"tlsRequired": true,
|
||||
"minTlsVersion": "1.3",
|
||||
"signedRequestsRequired": false,
|
||||
"rateLimits": {
|
||||
"requestsPerMinute": 60,
|
||||
"requestsPerHour": 1000
|
||||
}
|
||||
},
|
||||
"links": {
|
||||
"documentation": "https://kis.gov.lv/architecture",
|
||||
"support": "mailto:support@kis.gov.lv",
|
||||
"source": "https://github.com/kisc-gov-lv/MCP-KISC-architecture",
|
||||
"terms": "https://kis.gov.lv/terms",
|
||||
"privacy": "https://kis.gov.lv/privacy"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,6 @@
|
||||
Contact: mailto:security@kis.gov.lv
|
||||
Contact: https://kis.gov.lv/security
|
||||
Expires: 2027-12-31T23:59:59Z
|
||||
Preferred-Languages: lv, en
|
||||
Canonical: https://llm.kis.gov.lv/.well-known/security.txt
|
||||
Policy: https://kis.gov.lv/security-policy
|
||||
Reference in New Issue
Block a user