1
0
Files
2026-10-11 14:36:51 +03:00

6.1 KiB

VeriTrust MCPF Credential Submission

Overview

KISC already has a VeriTrust organization profile. This submission requests a MCPServerCredential for the new did:web:llm.kis.gov.lv identity.


Existing KISC Profile in VeriTrust

Holder DID: did:key:z6Mkuwv1z6y2yorbBf4LEkNzJCg16ERVfWE3bJEPKXtQm7a9
Public Alias: did:web:veritrust.vc:portal:company:df0684bd-b54a-4684-b3d6-93a3b1c4bcb9
Status: Verified


New Identity for MCP Server

DID: did:web:llm.kis.gov.lv
Public Key (multibase): z6MkjWGNnJsdyvutfbsytFJhkwDwyHkMkfWVL8X1fS1yBm2w
Service Endpoint: https://llm.kis.gov.lv/mcp
Manifest: https://llm.kis.gov.lv/.well-known/mcp/manifest.json


Submission Process

Step 1: Verify Local Deployment

Before submitting to VeriTrust, ensure:

# All .well-known endpoints accessible
curl https://llm.kis.gov.lv/.well-known/did.json
curl https://llm.kis.gov.lv/.well-known/mcp-trust-registry.json
curl https://llm.kis.gov.lv/.well-known/mcp/manifest.json

# MCP server operational
curl https://llm.kis.gov.lv/mcp-health

Step 2: Submit Credential Request

Method 1: Via VeriTrust Portal (Recommended)

  1. Log into VeriTrust portal: https://veritrust.vc/portal
  2. Navigate to your KISC organization profile
  3. Click "Request Credential" → "MCP Server Credential"
  4. Fill in form with data from mcp-server-request.json
  5. Upload or paste:
    • DID: did:web:llm.kis.gov.lv
    • Public key (multibase): z6MkjWGNnJsdyvutfbsytFJhkwDwyHkMkfWVL8X1fS1yBm2w
    • Endpoint: https://llm.kis.gov.lv/mcp
    • Manifest URL: https://llm.kis.gov.lv/.well-known/mcp/manifest.json
  6. Submit for review

Method 2: Via API (If Available)

# POST to VeriTrust credential issuance API
curl -X POST https://veritrust.vc/api/v1/credentials/issue \
  -H "Authorization: Bearer $VERITRUST_API_KEY" \
  -H "Content-Type: application/json" \
  -d @mcp-server-request.json

Method 3: Email Submission

Send mcp-server-request.json to: credentials@veritrust.vc

Include:

  • Subject: "KISC MCP Server Credential Request - did:web:llm.kis.gov.lv"
  • Body: Reference existing KISC profile (did:key:z6Mkuwv1z6y2yorbBf4LEkNzJCg16ERVfWE3bJEPKXtQm7a9)
  • Attach: mcp-server-request.json

Step 3: Verification by VeriTrust

VeriTrust will verify:

  1. ✅ KISC organization profile exists and is verified
  2. ✅ llm.kis.gov.lv domain is controlled by KISC
  3. ✅ DID document accessible at https://llm.kis.gov.lv/.well-known/did.json
  4. ✅ MCP manifest valid at https://llm.kis.gov.lv/.well-known/mcp/manifest.json
  5. ✅ Public key matches DID document
  6. ✅ Compliance claims are accurate (GDPR, NIS2)

Timeline: 1-5 business days (typically 1-2 days for verified organizations)


Step 4: Receive Credential

VeriTrust will provide:

{
  "@context": [
    "https://www.w3.org/2018/credentials/v1",
    "https://mcpf.dev/credentials/v1"
  ],
  "id": "https://veritrust.vc/credentials/[UUID]",
  "type": ["VerifiableCredential", "MCPServerCredential"],
  "issuer": {
    "id": "did:web:veritrust.vc",
    "name": "VeriTrust"
  },
  "issuanceDate": "2026-01-30T10:00:00Z",
  "expirationDate": "2027-01-30T10:00:00Z",
  "credentialSubject": {
    "id": "did:web:llm.kis.gov.lv#mcp-server",
    ...
  },
  "credentialStatus": {
    "id": "https://veritrust.vc/status/2026#94567",
    "type": "StatusList2021Entry",
    ...
  },
  "proof": {
    "type": "Ed25519Signature2020",
    "created": "2026-01-30T10:00:00Z",
    "verificationMethod": "did:web:veritrust.vc#key-1",
    "proofPurpose": "assertionMethod",
    "proofValue": "z5vgK8B..." // VeriTrust's cryptographic signature
  }
}

Step 5: Install Credential

Use the provided install-credential.sh script:

# On llm.kis.gov.lv server
cd /opt/kisc-llm/poc/deploy

# Save VeriTrust credential to temporary file
cat > /tmp/veritrust-credential.json << 'EOF'
{
  ... (paste VeriTrust-provided credential JSON) ...
}
EOF

# Run install script
./veritrust/install-credential.sh /tmp/veritrust-credential.json

# Verify installation
curl https://llm.kis.gov.lv/.well-known/credentials/mcp-server.json | jq

Step 6: Register in MCPF Registry

VeriTrust will automatically register the MCP server in their MCPF registry at https://mcp.veritrust.vc.

Verify registration:

# Search by country
curl "https://mcp.veritrust.vc/mcp/search?country=LV"

# Get specific server
curl "https://mcp.veritrust.vc/mcp/servers/did:web:llm.kis.gov.lv"

Expected response:

{
  "did": "did:web:llm.kis.gov.lv",
  "endpoint": "https://llm.kis.gov.lv/mcp",
  "manifest": "https://llm.kis.gov.lv/.well-known/mcp/manifest.json",
  "credentials": [
    "https://llm.kis.gov.lv/.well-known/credentials/mcp-server.json"
  ],
  "metadata": {
    "organization": "Kultūras informācijas sistēmu centrs",
    "country": "LV",
    "tags": ["architecture", "government", "latvia", "culture"],
    "status": "active"
  }
}

Troubleshooting

VeriTrust cannot verify domain ownership

Solution: Add DNS TXT record:

_veritrust.llm.kis.gov.lv TXT "did=did:web:llm.kis.gov.lv"

VeriTrust cannot fetch DID document

Solution: Verify HTTPS and CORS:

curl -I https://llm.kis.gov.lv/.well-known/did.json
# Should show: 
# HTTP/2 200
# access-control-allow-origin: *
# content-type: application/json

Credential issuance delayed

Solution: Contact VeriTrust support with:

  • Organization: KISC
  • Existing DID: did:key:z6Mkuwv1z6y2yorbBf4LEkNzJCg16ERVfWE3bJEPKXtQm7a9
  • New DID: did:web:llm.kis.gov.lv
  • Request ID: (if provided)

Contact

VeriTrust Support:

KISC Contact:

  • Rihards (VeriTrust relationship)
  • KISC IT operations team

Credential Renewal

Expiration: 1 year from issuance
Renewal Process: 30 days before expiration, VeriTrust will notify KISC via email
Action Required: Confirm renewal (usually automatic for verified organizations)


Version: 1.0
Last Updated: 2026-01-30
Status: Ready for Submission