1
0
Files
2026-10-11 14:36:51 +03:00

248 lines
6.1 KiB
Markdown

# VeriTrust MCPF Credential Submission
## Overview
KISC already has a VeriTrust organization profile. This submission requests a **MCPServerCredential** for the new `did:web:llm.kis.gov.lv` identity.
---
## Existing KISC Profile in VeriTrust
**Holder DID:** `did:key:z6Mkuwv1z6y2yorbBf4LEkNzJCg16ERVfWE3bJEPKXtQm7a9`
**Public Alias:** `did:web:veritrust.vc:portal:company:df0684bd-b54a-4684-b3d6-93a3b1c4bcb9`
**Status:** Verified
---
## New Identity for MCP Server
**DID:** `did:web:llm.kis.gov.lv`
**Public Key (multibase):** `z6MkjWGNnJsdyvutfbsytFJhkwDwyHkMkfWVL8X1fS1yBm2w`
**Service Endpoint:** `https://llm.kis.gov.lv/mcp`
**Manifest:** `https://llm.kis.gov.lv/.well-known/mcp/manifest.json`
---
## Submission Process
### Step 1: Verify Local Deployment
Before submitting to VeriTrust, ensure:
```bash
# All .well-known endpoints accessible
curl https://llm.kis.gov.lv/.well-known/did.json
curl https://llm.kis.gov.lv/.well-known/mcp-trust-registry.json
curl https://llm.kis.gov.lv/.well-known/mcp/manifest.json
# MCP server operational
curl https://llm.kis.gov.lv/mcp-health
```
---
### Step 2: Submit Credential Request
**Method 1: Via VeriTrust Portal (Recommended)**
1. Log into VeriTrust portal: https://veritrust.vc/portal
2. Navigate to your KISC organization profile
3. Click "Request Credential" → "MCP Server Credential"
4. Fill in form with data from `mcp-server-request.json`
5. Upload or paste:
- DID: `did:web:llm.kis.gov.lv`
- Public key (multibase): `z6MkjWGNnJsdyvutfbsytFJhkwDwyHkMkfWVL8X1fS1yBm2w`
- Endpoint: `https://llm.kis.gov.lv/mcp`
- Manifest URL: `https://llm.kis.gov.lv/.well-known/mcp/manifest.json`
6. Submit for review
**Method 2: Via API (If Available)**
```bash
# POST to VeriTrust credential issuance API
curl -X POST https://veritrust.vc/api/v1/credentials/issue \
-H "Authorization: Bearer $VERITRUST_API_KEY" \
-H "Content-Type: application/json" \
-d @mcp-server-request.json
```
**Method 3: Email Submission**
Send `mcp-server-request.json` to: credentials@veritrust.vc
Include:
- Subject: "KISC MCP Server Credential Request - did:web:llm.kis.gov.lv"
- Body: Reference existing KISC profile (did:key:z6Mkuwv1z6y2yorbBf4LEkNzJCg16ERVfWE3bJEPKXtQm7a9)
- Attach: mcp-server-request.json
---
### Step 3: Verification by VeriTrust
VeriTrust will verify:
1. ✅ KISC organization profile exists and is verified
2. ✅ `llm.kis.gov.lv` domain is controlled by KISC
3. ✅ DID document accessible at `https://llm.kis.gov.lv/.well-known/did.json`
4. ✅ MCP manifest valid at `https://llm.kis.gov.lv/.well-known/mcp/manifest.json`
5. ✅ Public key matches DID document
6. ✅ Compliance claims are accurate (GDPR, NIS2)
**Timeline:** 1-5 business days (typically 1-2 days for verified organizations)
---
### Step 4: Receive Credential
VeriTrust will provide:
```json
{
"@context": [
"https://www.w3.org/2018/credentials/v1",
"https://mcpf.dev/credentials/v1"
],
"id": "https://veritrust.vc/credentials/[UUID]",
"type": ["VerifiableCredential", "MCPServerCredential"],
"issuer": {
"id": "did:web:veritrust.vc",
"name": "VeriTrust"
},
"issuanceDate": "2026-01-30T10:00:00Z",
"expirationDate": "2027-01-30T10:00:00Z",
"credentialSubject": {
"id": "did:web:llm.kis.gov.lv#mcp-server",
...
},
"credentialStatus": {
"id": "https://veritrust.vc/status/2026#94567",
"type": "StatusList2021Entry",
...
},
"proof": {
"type": "Ed25519Signature2020",
"created": "2026-01-30T10:00:00Z",
"verificationMethod": "did:web:veritrust.vc#key-1",
"proofPurpose": "assertionMethod",
"proofValue": "z5vgK8B..." // VeriTrust's cryptographic signature
}
}
```
---
### Step 5: Install Credential
Use the provided `install-credential.sh` script:
```bash
# On llm.kis.gov.lv server
cd /opt/kisc-llm/poc/deploy
# Save VeriTrust credential to temporary file
cat > /tmp/veritrust-credential.json << 'EOF'
{
... (paste VeriTrust-provided credential JSON) ...
}
EOF
# Run install script
./veritrust/install-credential.sh /tmp/veritrust-credential.json
# Verify installation
curl https://llm.kis.gov.lv/.well-known/credentials/mcp-server.json | jq
```
---
### Step 6: Register in MCPF Registry
VeriTrust will automatically register the MCP server in their MCPF registry at `https://mcp.veritrust.vc`.
Verify registration:
```bash
# Search by country
curl "https://mcp.veritrust.vc/mcp/search?country=LV"
# Get specific server
curl "https://mcp.veritrust.vc/mcp/servers/did:web:llm.kis.gov.lv"
```
Expected response:
```json
{
"did": "did:web:llm.kis.gov.lv",
"endpoint": "https://llm.kis.gov.lv/mcp",
"manifest": "https://llm.kis.gov.lv/.well-known/mcp/manifest.json",
"credentials": [
"https://llm.kis.gov.lv/.well-known/credentials/mcp-server.json"
],
"metadata": {
"organization": "Kultūras informācijas sistēmu centrs",
"country": "LV",
"tags": ["architecture", "government", "latvia", "culture"],
"status": "active"
}
}
```
---
## Troubleshooting
### VeriTrust cannot verify domain ownership
**Solution:** Add DNS TXT record:
```
_veritrust.llm.kis.gov.lv TXT "did=did:web:llm.kis.gov.lv"
```
### VeriTrust cannot fetch DID document
**Solution:** Verify HTTPS and CORS:
```bash
curl -I https://llm.kis.gov.lv/.well-known/did.json
# Should show:
# HTTP/2 200
# access-control-allow-origin: *
# content-type: application/json
```
### Credential issuance delayed
**Solution:** Contact VeriTrust support with:
- Organization: KISC
- Existing DID: did:key:z6Mkuwv1z6y2yorbBf4LEkNzJCg16ERVfWE3bJEPKXtQm7a9
- New DID: did:web:llm.kis.gov.lv
- Request ID: (if provided)
---
## Contact
**VeriTrust Support:**
- Website: https://veritrust.vc
- Email: support@veritrust.vc (or credentials@veritrust.vc)
- Portal: https://veritrust.vc/portal
**KISC Contact:**
- Rihards (VeriTrust relationship)
- KISC IT operations team
---
## Credential Renewal
**Expiration:** 1 year from issuance
**Renewal Process:** 30 days before expiration, VeriTrust will notify KISC via email
**Action Required:** Confirm renewal (usually automatic for verified organizations)
---
**Version:** 1.0
**Last Updated:** 2026-01-30
**Status:** Ready for Submission