KISC arch init
This commit is contained in:
@@ -0,0 +1,247 @@
|
||||
# VeriTrust MCPF Credential Submission
|
||||
|
||||
## Overview
|
||||
|
||||
KISC already has a VeriTrust organization profile. This submission requests a **MCPServerCredential** for the new `did:web:llm.kis.gov.lv` identity.
|
||||
|
||||
---
|
||||
|
||||
## Existing KISC Profile in VeriTrust
|
||||
|
||||
**Holder DID:** `did:key:z6Mkuwv1z6y2yorbBf4LEkNzJCg16ERVfWE3bJEPKXtQm7a9`
|
||||
**Public Alias:** `did:web:veritrust.vc:portal:company:df0684bd-b54a-4684-b3d6-93a3b1c4bcb9`
|
||||
**Status:** Verified
|
||||
|
||||
---
|
||||
|
||||
## New Identity for MCP Server
|
||||
|
||||
**DID:** `did:web:llm.kis.gov.lv`
|
||||
**Public Key (multibase):** `z6MkjWGNnJsdyvutfbsytFJhkwDwyHkMkfWVL8X1fS1yBm2w`
|
||||
**Service Endpoint:** `https://llm.kis.gov.lv/mcp`
|
||||
**Manifest:** `https://llm.kis.gov.lv/.well-known/mcp/manifest.json`
|
||||
|
||||
---
|
||||
|
||||
## Submission Process
|
||||
|
||||
### Step 1: Verify Local Deployment
|
||||
|
||||
Before submitting to VeriTrust, ensure:
|
||||
|
||||
```bash
|
||||
# All .well-known endpoints accessible
|
||||
curl https://llm.kis.gov.lv/.well-known/did.json
|
||||
curl https://llm.kis.gov.lv/.well-known/mcp-trust-registry.json
|
||||
curl https://llm.kis.gov.lv/.well-known/mcp/manifest.json
|
||||
|
||||
# MCP server operational
|
||||
curl https://llm.kis.gov.lv/mcp-health
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
### Step 2: Submit Credential Request
|
||||
|
||||
**Method 1: Via VeriTrust Portal (Recommended)**
|
||||
|
||||
1. Log into VeriTrust portal: https://veritrust.vc/portal
|
||||
2. Navigate to your KISC organization profile
|
||||
3. Click "Request Credential" → "MCP Server Credential"
|
||||
4. Fill in form with data from `mcp-server-request.json`
|
||||
5. Upload or paste:
|
||||
- DID: `did:web:llm.kis.gov.lv`
|
||||
- Public key (multibase): `z6MkjWGNnJsdyvutfbsytFJhkwDwyHkMkfWVL8X1fS1yBm2w`
|
||||
- Endpoint: `https://llm.kis.gov.lv/mcp`
|
||||
- Manifest URL: `https://llm.kis.gov.lv/.well-known/mcp/manifest.json`
|
||||
6. Submit for review
|
||||
|
||||
**Method 2: Via API (If Available)**
|
||||
|
||||
```bash
|
||||
# POST to VeriTrust credential issuance API
|
||||
curl -X POST https://veritrust.vc/api/v1/credentials/issue \
|
||||
-H "Authorization: Bearer $VERITRUST_API_KEY" \
|
||||
-H "Content-Type: application/json" \
|
||||
-d @mcp-server-request.json
|
||||
```
|
||||
|
||||
**Method 3: Email Submission**
|
||||
|
||||
Send `mcp-server-request.json` to: credentials@veritrust.vc
|
||||
|
||||
Include:
|
||||
- Subject: "KISC MCP Server Credential Request - did:web:llm.kis.gov.lv"
|
||||
- Body: Reference existing KISC profile (did:key:z6Mkuwv1z6y2yorbBf4LEkNzJCg16ERVfWE3bJEPKXtQm7a9)
|
||||
- Attach: mcp-server-request.json
|
||||
|
||||
---
|
||||
|
||||
### Step 3: Verification by VeriTrust
|
||||
|
||||
VeriTrust will verify:
|
||||
|
||||
1. ✅ KISC organization profile exists and is verified
|
||||
2. ✅ `llm.kis.gov.lv` domain is controlled by KISC
|
||||
3. ✅ DID document accessible at `https://llm.kis.gov.lv/.well-known/did.json`
|
||||
4. ✅ MCP manifest valid at `https://llm.kis.gov.lv/.well-known/mcp/manifest.json`
|
||||
5. ✅ Public key matches DID document
|
||||
6. ✅ Compliance claims are accurate (GDPR, NIS2)
|
||||
|
||||
**Timeline:** 1-5 business days (typically 1-2 days for verified organizations)
|
||||
|
||||
---
|
||||
|
||||
### Step 4: Receive Credential
|
||||
|
||||
VeriTrust will provide:
|
||||
|
||||
```json
|
||||
{
|
||||
"@context": [
|
||||
"https://www.w3.org/2018/credentials/v1",
|
||||
"https://mcpf.dev/credentials/v1"
|
||||
],
|
||||
"id": "https://veritrust.vc/credentials/[UUID]",
|
||||
"type": ["VerifiableCredential", "MCPServerCredential"],
|
||||
"issuer": {
|
||||
"id": "did:web:veritrust.vc",
|
||||
"name": "VeriTrust"
|
||||
},
|
||||
"issuanceDate": "2026-01-30T10:00:00Z",
|
||||
"expirationDate": "2027-01-30T10:00:00Z",
|
||||
"credentialSubject": {
|
||||
"id": "did:web:llm.kis.gov.lv#mcp-server",
|
||||
...
|
||||
},
|
||||
"credentialStatus": {
|
||||
"id": "https://veritrust.vc/status/2026#94567",
|
||||
"type": "StatusList2021Entry",
|
||||
...
|
||||
},
|
||||
"proof": {
|
||||
"type": "Ed25519Signature2020",
|
||||
"created": "2026-01-30T10:00:00Z",
|
||||
"verificationMethod": "did:web:veritrust.vc#key-1",
|
||||
"proofPurpose": "assertionMethod",
|
||||
"proofValue": "z5vgK8B..." // VeriTrust's cryptographic signature
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
### Step 5: Install Credential
|
||||
|
||||
Use the provided `install-credential.sh` script:
|
||||
|
||||
```bash
|
||||
# On llm.kis.gov.lv server
|
||||
cd /opt/kisc-llm/poc/deploy
|
||||
|
||||
# Save VeriTrust credential to temporary file
|
||||
cat > /tmp/veritrust-credential.json << 'EOF'
|
||||
{
|
||||
... (paste VeriTrust-provided credential JSON) ...
|
||||
}
|
||||
EOF
|
||||
|
||||
# Run install script
|
||||
./veritrust/install-credential.sh /tmp/veritrust-credential.json
|
||||
|
||||
# Verify installation
|
||||
curl https://llm.kis.gov.lv/.well-known/credentials/mcp-server.json | jq
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
### Step 6: Register in MCPF Registry
|
||||
|
||||
VeriTrust will automatically register the MCP server in their MCPF registry at `https://mcp.veritrust.vc`.
|
||||
|
||||
Verify registration:
|
||||
|
||||
```bash
|
||||
# Search by country
|
||||
curl "https://mcp.veritrust.vc/mcp/search?country=LV"
|
||||
|
||||
# Get specific server
|
||||
curl "https://mcp.veritrust.vc/mcp/servers/did:web:llm.kis.gov.lv"
|
||||
```
|
||||
|
||||
Expected response:
|
||||
```json
|
||||
{
|
||||
"did": "did:web:llm.kis.gov.lv",
|
||||
"endpoint": "https://llm.kis.gov.lv/mcp",
|
||||
"manifest": "https://llm.kis.gov.lv/.well-known/mcp/manifest.json",
|
||||
"credentials": [
|
||||
"https://llm.kis.gov.lv/.well-known/credentials/mcp-server.json"
|
||||
],
|
||||
"metadata": {
|
||||
"organization": "Kultūras informācijas sistēmu centrs",
|
||||
"country": "LV",
|
||||
"tags": ["architecture", "government", "latvia", "culture"],
|
||||
"status": "active"
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## Troubleshooting
|
||||
|
||||
### VeriTrust cannot verify domain ownership
|
||||
|
||||
**Solution:** Add DNS TXT record:
|
||||
|
||||
```
|
||||
_veritrust.llm.kis.gov.lv TXT "did=did:web:llm.kis.gov.lv"
|
||||
```
|
||||
|
||||
### VeriTrust cannot fetch DID document
|
||||
|
||||
**Solution:** Verify HTTPS and CORS:
|
||||
|
||||
```bash
|
||||
curl -I https://llm.kis.gov.lv/.well-known/did.json
|
||||
# Should show:
|
||||
# HTTP/2 200
|
||||
# access-control-allow-origin: *
|
||||
# content-type: application/json
|
||||
```
|
||||
|
||||
### Credential issuance delayed
|
||||
|
||||
**Solution:** Contact VeriTrust support with:
|
||||
- Organization: KISC
|
||||
- Existing DID: did:key:z6Mkuwv1z6y2yorbBf4LEkNzJCg16ERVfWE3bJEPKXtQm7a9
|
||||
- New DID: did:web:llm.kis.gov.lv
|
||||
- Request ID: (if provided)
|
||||
|
||||
---
|
||||
|
||||
## Contact
|
||||
|
||||
**VeriTrust Support:**
|
||||
- Website: https://veritrust.vc
|
||||
- Email: support@veritrust.vc (or credentials@veritrust.vc)
|
||||
- Portal: https://veritrust.vc/portal
|
||||
|
||||
**KISC Contact:**
|
||||
- Rihards (VeriTrust relationship)
|
||||
- KISC IT operations team
|
||||
|
||||
---
|
||||
|
||||
## Credential Renewal
|
||||
|
||||
**Expiration:** 1 year from issuance
|
||||
**Renewal Process:** 30 days before expiration, VeriTrust will notify KISC via email
|
||||
**Action Required:** Confirm renewal (usually automatic for verified organizations)
|
||||
|
||||
---
|
||||
|
||||
**Version:** 1.0
|
||||
**Last Updated:** 2026-01-30
|
||||
**Status:** Ready for Submission
|
||||
Reference in New Issue
Block a user