diff --git a/presentations/signatif-intro.pptx b/presentations/signatif-intro.pptx index afeb3bd..3d2b8bf 100644 Binary files a/presentations/signatif-intro.pptx and b/presentations/signatif-intro.pptx differ diff --git a/sources/data/08-artifact-format-rc.yaml b/sources/data/08-artifact-format-rc.yaml index b398680..592e793 100644 --- a/sources/data/08-artifact-format-rc.yaml +++ b/sources/data/08-artifact-format-rc.yaml @@ -36,7 +36,10 @@ groups: identifier_fragment: signer-identification statement: A signature wrapper shall reference or embed the signer's public key or end certificate, enabling the verifier to locate the key and its delegation - chain. + chain. In publicly presentable artifacts and passports, the signer identity of a + co-signature block shall be a key fingerprint or pseudonym; named-identity + binding shall be held in an access-controlled register by the responsible + authority. guidance: - "Signer identifiers are URIs (<>)." @@ -88,6 +91,8 @@ groups: algorithm and parameters, dimension tag, and signature over the canonical payload. guidance: - The dimension tag identifies the trust dimension this co-signature attests. + - "Schemes whose attesting subjects are individuals should use rotating or purpose-bound operator keys, or privacy-preserving credentials, to limit cross-artifact linkability." + - name: Co-signature independent verification identifier_fragment: cosignature-independent-verification diff --git a/sources/data/13-transparency-cc.yaml b/sources/data/13-transparency-cc.yaml index d994623..fd8ffd8 100644 --- a/sources/data/13-transparency-cc.yaml +++ b/sources/data/13-transparency-cc.yaml @@ -82,6 +82,18 @@ groups: is validated independently. type: Conformance + - name: Log content minimization test + identifier_fragment: log-content-minimization + targets: + - /req/transparency/log-content-minimization + purpose: Verify log structures carry no directly identifying personal data and that + named-identity binding sits in access-controlled registers. + method: Inspect serialized log leaves, inclusion proofs, and tree heads for names, + identifiers, or linkable personal data; verify only digests and tags appear. + Attempt to resolve a signer from a public artifact without the authority register + and confirm the register is access-controlled. + type: Conformance + - name: Log retention test identifier_fragment: log-retention targets: diff --git a/sources/data/13-transparency-rc.yaml b/sources/data/13-transparency-rc.yaml index aeb5461..7c54194 100644 --- a/sources/data/13-transparency-rc.yaml +++ b/sources/data/13-transparency-rc.yaml @@ -21,6 +21,8 @@ groups: - Domain separation prevents second-preimage attacks. RFC 6962 uses 0x00 prefix for leaves and 0x01 prefix for internal nodes. - The Merkle tree semantics follow RFC 6962. + - "Append-only history records that attestations were issued, not that their content remains accurate; rectification flows through supersession and the revocation propagation of clause 11." + - name: Inclusion proof format identifier_fragment: inclusion-proof @@ -75,6 +77,17 @@ groups: - Each inclusion proof is validated independently. - No single log operator controls the record. + - name: Log content minimization + identifier_fragment: log-content-minimization + statement: Log leaves, inclusion proofs, and tree heads shall contain no directly + identifying personal data; personal data referenced by an artifact shall be held in + access-controlled registers by the responsible authority, with revocation and key + rotation serving as the mechanism for withdrawal of validity. + guidance: + - "The log records issuance, not truth: corrections are made by superseding + attestations and re-issuance, never by editing history." + + - name: Log retention identifier_fragment: log-retention statement: A recognized transparency log shall retain its append-only history, and its @@ -82,6 +95,8 @@ groups: plus grace periods that the deployment serves. guidance: - Retention obligations transfer with log succession per the scheme's governance. + - "Retention is bounded by purpose: the scheme's retention policy defines deletion and suppression criteria once the served validity period ends." + - name: Consistency proofs identifier_fragment: consistency-proofs diff --git a/sources/data/17-ceremony-rc.yaml b/sources/data/17-ceremony-rc.yaml index e2cc57a..f79575a 100644 --- a/sources/data/17-ceremony-rc.yaml +++ b/sources/data/17-ceremony-rc.yaml @@ -36,6 +36,8 @@ groups: transcript custody shall transfer to a successor or escrow designated by the scheme's governance. guidance: + - "Transcript retention follows the scheme's retention policy, which defines deletion and suppression criteria for personal data of key holders once the served period ends." + - name: Transcript transparency log cross-reference identifier_fragment: transcript-log-cross-reference diff --git a/sources/data/18-manifest-rc.yaml b/sources/data/18-manifest-rc.yaml index 9c0ad67..c5ff45f 100644 --- a/sources/data/18-manifest-rc.yaml +++ b/sources/data/18-manifest-rc.yaml @@ -43,6 +43,8 @@ groups: mirrors with their endpoints and public keys, and the multi-log attestation policy parameters if applicable. guidance: + - "The manifest documents the jurisdictional scope of log operators and mirrors and the basis for any cross-border transfer of personal data." + - name: Manifest validation — acyclic graph identifier_fragment: manifest-validation-acyclic diff --git a/sources/data/19-governance-rc.yaml b/sources/data/19-governance-rc.yaml index 8310ee5..663f066 100644 --- a/sources/data/19-governance-rc.yaml +++ b/sources/data/19-governance-rc.yaml @@ -30,6 +30,8 @@ groups: guidance: - ISO/IEC 27001, WebTrust for CAs, and ETSI EN 319 411 are recognized ISMS frameworks. - Audit attestations shall be published. + - "Schemes processing personal data define a privacy policy covering lawful basis, information duties to attesting subjects, and the retention schedule." + - name: Issuing authority organizational assurance identifier_fragment: issuing-authority-assurance