248 lines
6.1 KiB
Markdown
248 lines
6.1 KiB
Markdown
# VeriTrust MCPF Credential Submission
|
|
|
|
## Overview
|
|
|
|
KISC already has a VeriTrust organization profile. This submission requests a **MCPServerCredential** for the new `did:web:llm.kis.gov.lv` identity.
|
|
|
|
---
|
|
|
|
## Existing KISC Profile in VeriTrust
|
|
|
|
**Holder DID:** `did:key:z6Mkuwv1z6y2yorbBf4LEkNzJCg16ERVfWE3bJEPKXtQm7a9`
|
|
**Public Alias:** `did:web:veritrust.vc:portal:company:df0684bd-b54a-4684-b3d6-93a3b1c4bcb9`
|
|
**Status:** Verified
|
|
|
|
---
|
|
|
|
## New Identity for MCP Server
|
|
|
|
**DID:** `did:web:llm.kis.gov.lv`
|
|
**Public Key (multibase):** `z6MkjWGNnJsdyvutfbsytFJhkwDwyHkMkfWVL8X1fS1yBm2w`
|
|
**Service Endpoint:** `https://llm.kis.gov.lv/mcp`
|
|
**Manifest:** `https://llm.kis.gov.lv/.well-known/mcp/manifest.json`
|
|
|
|
---
|
|
|
|
## Submission Process
|
|
|
|
### Step 1: Verify Local Deployment
|
|
|
|
Before submitting to VeriTrust, ensure:
|
|
|
|
```bash
|
|
# All .well-known endpoints accessible
|
|
curl https://llm.kis.gov.lv/.well-known/did.json
|
|
curl https://llm.kis.gov.lv/.well-known/mcp-trust-registry.json
|
|
curl https://llm.kis.gov.lv/.well-known/mcp/manifest.json
|
|
|
|
# MCP server operational
|
|
curl https://llm.kis.gov.lv/mcp-health
|
|
```
|
|
|
|
---
|
|
|
|
### Step 2: Submit Credential Request
|
|
|
|
**Method 1: Via VeriTrust Portal (Recommended)**
|
|
|
|
1. Log into VeriTrust portal: https://veritrust.vc/portal
|
|
2. Navigate to your KISC organization profile
|
|
3. Click "Request Credential" → "MCP Server Credential"
|
|
4. Fill in form with data from `mcp-server-request.json`
|
|
5. Upload or paste:
|
|
- DID: `did:web:llm.kis.gov.lv`
|
|
- Public key (multibase): `z6MkjWGNnJsdyvutfbsytFJhkwDwyHkMkfWVL8X1fS1yBm2w`
|
|
- Endpoint: `https://llm.kis.gov.lv/mcp`
|
|
- Manifest URL: `https://llm.kis.gov.lv/.well-known/mcp/manifest.json`
|
|
6. Submit for review
|
|
|
|
**Method 2: Via API (If Available)**
|
|
|
|
```bash
|
|
# POST to VeriTrust credential issuance API
|
|
curl -X POST https://veritrust.vc/api/v1/credentials/issue \
|
|
-H "Authorization: Bearer $VERITRUST_API_KEY" \
|
|
-H "Content-Type: application/json" \
|
|
-d @mcp-server-request.json
|
|
```
|
|
|
|
**Method 3: Email Submission**
|
|
|
|
Send `mcp-server-request.json` to: credentials@veritrust.vc
|
|
|
|
Include:
|
|
- Subject: "KISC MCP Server Credential Request - did:web:llm.kis.gov.lv"
|
|
- Body: Reference existing KISC profile (did:key:z6Mkuwv1z6y2yorbBf4LEkNzJCg16ERVfWE3bJEPKXtQm7a9)
|
|
- Attach: mcp-server-request.json
|
|
|
|
---
|
|
|
|
### Step 3: Verification by VeriTrust
|
|
|
|
VeriTrust will verify:
|
|
|
|
1. ✅ KISC organization profile exists and is verified
|
|
2. ✅ `llm.kis.gov.lv` domain is controlled by KISC
|
|
3. ✅ DID document accessible at `https://llm.kis.gov.lv/.well-known/did.json`
|
|
4. ✅ MCP manifest valid at `https://llm.kis.gov.lv/.well-known/mcp/manifest.json`
|
|
5. ✅ Public key matches DID document
|
|
6. ✅ Compliance claims are accurate (GDPR, NIS2)
|
|
|
|
**Timeline:** 1-5 business days (typically 1-2 days for verified organizations)
|
|
|
|
---
|
|
|
|
### Step 4: Receive Credential
|
|
|
|
VeriTrust will provide:
|
|
|
|
```json
|
|
{
|
|
"@context": [
|
|
"https://www.w3.org/2018/credentials/v1",
|
|
"https://mcpf.dev/credentials/v1"
|
|
],
|
|
"id": "https://veritrust.vc/credentials/[UUID]",
|
|
"type": ["VerifiableCredential", "MCPServerCredential"],
|
|
"issuer": {
|
|
"id": "did:web:veritrust.vc",
|
|
"name": "VeriTrust"
|
|
},
|
|
"issuanceDate": "2026-01-30T10:00:00Z",
|
|
"expirationDate": "2027-01-30T10:00:00Z",
|
|
"credentialSubject": {
|
|
"id": "did:web:llm.kis.gov.lv#mcp-server",
|
|
...
|
|
},
|
|
"credentialStatus": {
|
|
"id": "https://veritrust.vc/status/2026#94567",
|
|
"type": "StatusList2021Entry",
|
|
...
|
|
},
|
|
"proof": {
|
|
"type": "Ed25519Signature2020",
|
|
"created": "2026-01-30T10:00:00Z",
|
|
"verificationMethod": "did:web:veritrust.vc#key-1",
|
|
"proofPurpose": "assertionMethod",
|
|
"proofValue": "z5vgK8B..." // VeriTrust's cryptographic signature
|
|
}
|
|
}
|
|
```
|
|
|
|
---
|
|
|
|
### Step 5: Install Credential
|
|
|
|
Use the provided `install-credential.sh` script:
|
|
|
|
```bash
|
|
# On llm.kis.gov.lv server
|
|
cd /opt/kisc-llm/poc/deploy
|
|
|
|
# Save VeriTrust credential to temporary file
|
|
cat > /tmp/veritrust-credential.json << 'EOF'
|
|
{
|
|
... (paste VeriTrust-provided credential JSON) ...
|
|
}
|
|
EOF
|
|
|
|
# Run install script
|
|
./veritrust/install-credential.sh /tmp/veritrust-credential.json
|
|
|
|
# Verify installation
|
|
curl https://llm.kis.gov.lv/.well-known/credentials/mcp-server.json | jq
|
|
```
|
|
|
|
---
|
|
|
|
### Step 6: Register in MCPF Registry
|
|
|
|
VeriTrust will automatically register the MCP server in their MCPF registry at `https://mcp.veritrust.vc`.
|
|
|
|
Verify registration:
|
|
|
|
```bash
|
|
# Search by country
|
|
curl "https://mcp.veritrust.vc/mcp/search?country=LV"
|
|
|
|
# Get specific server
|
|
curl "https://mcp.veritrust.vc/mcp/servers/did:web:llm.kis.gov.lv"
|
|
```
|
|
|
|
Expected response:
|
|
```json
|
|
{
|
|
"did": "did:web:llm.kis.gov.lv",
|
|
"endpoint": "https://llm.kis.gov.lv/mcp",
|
|
"manifest": "https://llm.kis.gov.lv/.well-known/mcp/manifest.json",
|
|
"credentials": [
|
|
"https://llm.kis.gov.lv/.well-known/credentials/mcp-server.json"
|
|
],
|
|
"metadata": {
|
|
"organization": "Kultūras informācijas sistēmu centrs",
|
|
"country": "LV",
|
|
"tags": ["architecture", "government", "latvia", "culture"],
|
|
"status": "active"
|
|
}
|
|
}
|
|
```
|
|
|
|
---
|
|
|
|
## Troubleshooting
|
|
|
|
### VeriTrust cannot verify domain ownership
|
|
|
|
**Solution:** Add DNS TXT record:
|
|
|
|
```
|
|
_veritrust.llm.kis.gov.lv TXT "did=did:web:llm.kis.gov.lv"
|
|
```
|
|
|
|
### VeriTrust cannot fetch DID document
|
|
|
|
**Solution:** Verify HTTPS and CORS:
|
|
|
|
```bash
|
|
curl -I https://llm.kis.gov.lv/.well-known/did.json
|
|
# Should show:
|
|
# HTTP/2 200
|
|
# access-control-allow-origin: *
|
|
# content-type: application/json
|
|
```
|
|
|
|
### Credential issuance delayed
|
|
|
|
**Solution:** Contact VeriTrust support with:
|
|
- Organization: KISC
|
|
- Existing DID: did:key:z6Mkuwv1z6y2yorbBf4LEkNzJCg16ERVfWE3bJEPKXtQm7a9
|
|
- New DID: did:web:llm.kis.gov.lv
|
|
- Request ID: (if provided)
|
|
|
|
---
|
|
|
|
## Contact
|
|
|
|
**VeriTrust Support:**
|
|
- Website: https://veritrust.vc
|
|
- Email: support@veritrust.vc (or credentials@veritrust.vc)
|
|
- Portal: https://veritrust.vc/portal
|
|
|
|
**KISC Contact:**
|
|
- Rihards (VeriTrust relationship)
|
|
- KISC IT operations team
|
|
|
|
---
|
|
|
|
## Credential Renewal
|
|
|
|
**Expiration:** 1 year from issuance
|
|
**Renewal Process:** 30 days before expiration, VeriTrust will notify KISC via email
|
|
**Action Required:** Confirm renewal (usually automatic for verified organizations)
|
|
|
|
---
|
|
|
|
**Version:** 1.0
|
|
**Last Updated:** 2026-01-30
|
|
**Status:** Ready for Submission
|