{"_id":"@attestto/trust","_rev":"4-9cd96a0e85676615f3dfd6687674b8e7","name":"@attestto/trust","dist-tags":{"latest":"1.3.0"},"versions":{"1.0.0":{"name":"@attestto/trust","version":"1.0.0","keywords":["pki","x509","trust-anchors","costa-rica","firma-digital","bccr","sinpe","brazil","icp-brasil"],"author":{"name":"Attestto","email":"hello@attestto.com"},"license":"Apache-2.0","_id":"@attestto/trust@1.0.0","maintainers":[{"name":"chongkan","email":"e.chongkan@gmail.com"}],"homepage":"https://trust.attestto.org","bugs":{"url":"https://github.com/Attestto-com/attestto-trust/issues"},"dist":{"shasum":"e79e4209db08c064c55f1af9a7d517640a46c941","tarball":"https://registry.npmjs.org/@attestto/trust/-/trust-1.0.0.tgz","fileCount":45,"integrity":"sha512-6FoibuGwPbD7yn3lsqFYnrGbH2MqkNRbqM0w1M7Tqo3bFRVHJNr4R4ywz/c6WV31j6/TZ5iUf0WtH13wqejkVQ==","signatures":[{"sig":"MEUCIQCje/sbvQbscmpsVPebVppBYiKEUDX6WWyomEXcmuSuOQIgYggcWHdzzNB8WWtDQrg5h9gTeQEJpgAYGUk7mN8NwCM=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":273876},"main":"index.js","type":"module","types":"./index.d.ts","exports":{".":"./index.js","./ar":"./countries/ar/index.js","./br":"./countries/br/index.js","./cr":"./countries/cr/index.js","./es":"./countries/es/index.js","./pe":"./countries/pe/index.js","./ar/pems/*":"./countries/ar/current/*.pem","./br/pems/*":"./countries/br/current/*.pem","./cr/pems/*":"./countries/cr/current/*.pem","./es/pems/*":"./countries/es/current/*.pem","./pe/pems/*":"./countries/pe/current/*.pem"},"funding":"https://github.com/sponsors/Attestto-com","gitHead":"a6a715013fb260408891c530c6859ab0279db625","scripts":{"test":"node --test tests/*.mjs","generate":"node scripts/generate-exports.mjs","prepublishOnly":"npm test"},"_npmUser":{"name":"chongkan","email":"e.chongkan@gmail.com"},"repository":{"url":"git+https://github.com/Attestto-com/attestto-trust.git","type":"git"},"_npmVersion":"11.9.0","description":"Independent public mirror of X.509 trust anchors for national digital signature infrastructures. Countries: Costa Rica, Brazil, Argentina, Spain, Peru. Live directory at trust.attestto.org.","directories":{},"_nodeVersion":"25.6.1","_hasShrinkwrap":false,"devDependencies":{"node-forge":"^1.4.0","@peculiar/x509":"^2.0.0","reflect-metadata":"^0.2.2"},"_npmOperationalInternal":{"tmp":"tmp/trust_1.0.0_1784807399325_0.6406961693616053","host":"s3://npm-registry-packages-npm-production"}},"1.1.0":{"name":"@attestto/trust","version":"1.1.0","keywords":["pki","x509","trust-anchors","eidas","trusted-list","digital-signature","did-pki","gleif","vlei","firma-digital","icp-brasil"],"author":{"name":"Attestto","email":"hello@attestto.com"},"license":"Apache-2.0","_id":"@attestto/trust@1.1.0","maintainers":[{"name":"chongkan","email":"e.chongkan@gmail.com"}],"homepage":"https://trust.attestto.org","bugs":{"url":"https://github.com/Attestto-com/attestto-trust/issues"},"dist":{"shasum":"5f8f3e4f587b8cb2097454ee060c2f25d92e2268","tarball":"https://registry.npmjs.org/@attestto/trust/-/trust-1.1.0.tgz","fileCount":1050,"integrity":"sha512-9RBFsLGNSu3VfAzZFC3oQXyVpCButRK2a+7CUwClnoq2N0GZTwkbLaJOfRKMMCetC9+1lbuahym/bU9IwrDmfA==","signatures":[{"sig":"MEQCIFQ0ex138Zutc6tCfFqQ+Hu1jaOsw9QN/ampKAeXUwerAiApESmYR3DUJTglLy1026SOelAhmmGcWeEjAV3Q8ZvfBA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":6862499},"main":"index.js","type":"module","types":"./index.d.ts","exports":{".":"./index.js","./ar":"./countries/ar/index.js","./at":"./countries/at/index.js","./be":"./countries/be/index.js","./br":"./countries/br/index.js","./cr":"./countries/cr/index.js","./cz":"./countries/cz/index.js","./de":"./countries/de/index.js","./dk":"./countries/dk/index.js","./ee":"./countries/ee/index.js","./es":"./countries/es/index.js","./fi":"./countries/fi/index.js","./fr":"./countries/fr/index.js","./gr":"./countries/gr/index.js","./hu":"./countries/hu/index.js","./it":"./countries/it/index.js","./lt":"./countries/lt/index.js","./lv":"./countries/lv/index.js","./nl":"./countries/nl/index.js","./no":"./countries/no/index.js","./pe":"./countries/pe/index.js","./pl":"./countries/pl/index.js","./pt":"./countries/pt/index.js","./se":"./countries/se/index.js","./ar/pems/*":"./countries/ar/current/*.pem","./at/pems/*":"./countries/at/current/*.pem","./be/pems/*":"./countries/be/current/*.pem","./br/pems/*":"./countries/br/current/*.pem","./cr/pems/*":"./countries/cr/current/*.pem","./cz/pems/*":"./countries/cz/current/*.pem","./de/pems/*":"./countries/de/current/*.pem","./dk/pems/*":"./countries/dk/current/*.pem","./ee/pems/*":"./countries/ee/current/*.pem","./es/pems/*":"./countries/es/current/*.pem","./fi/pems/*":"./countries/fi/current/*.pem","./fr/pems/*":"./countries/fr/current/*.pem","./gr/pems/*":"./countries/gr/current/*.pem","./hu/pems/*":"./countries/hu/current/*.pem","./it/pems/*":"./countries/it/current/*.pem","./lt/pems/*":"./countries/lt/current/*.pem","./lv/pems/*":"./countries/lv/current/*.pem","./nl/pems/*":"./countries/nl/current/*.pem","./no/pems/*":"./countries/no/current/*.pem","./pe/pems/*":"./countries/pe/current/*.pem","./pl/pems/*":"./countries/pl/current/*.pem","./pt/pems/*":"./countries/pt/current/*.pem","./se/pems/*":"./countries/se/current/*.pem","./anchors/gleif-vlei":"./anchors/gleif-vlei/meta.json"},"funding":"https://github.com/sponsors/Attestto-com","gitHead":"8bcc94d2fe4bac0932736f1437626ce0a53d66c6","scripts":{"test":"node --test tests/*.mjs","generate":"node scripts/generate-exports.mjs","prepublishOnly":"npm test"},"_npmUser":{"name":"chongkan","email":"e.chongkan@gmail.com"},"repository":{"url":"git+https://github.com/Attestto-com/attestto-trust.git","type":"git"},"_npmVersion":"11.9.0","description":"Independent public mirror of X.509 trust anchors for national digital signature infrastructures (22 countries across Latin America and the EU/EEA), plus GLEIF vLEI organizational-identity root of trust. Live directory at trust.attestto.org.","directories":{},"_nodeVersion":"25.6.1","_hasShrinkwrap":false,"devDependencies":{"xadesjs":"^2.6.7","node-forge":"^1.4.0","@peculiar/x509":"^2.0.0","@xmldom/xmldom":"^0.8.13","reflect-metadata":"^0.2.2"},"_npmOperationalInternal":{"tmp":"tmp/trust_1.1.0_1784837690564_0.11042692928773645","host":"s3://npm-registry-packages-npm-production"}},"1.2.0":{"name":"@attestto/trust","version":"1.2.0","keywords":["pki","x509","trust-anchors","eidas","trusted-list","digital-signature","did-pki","gleif","vlei","firma-digital","icp-brasil"],"author":{"name":"Attestto","email":"hello@attestto.com"},"license":"Apache-2.0","_id":"@attestto/trust@1.2.0","maintainers":[{"name":"chongkan","email":"e.chongkan@gmail.com"}],"homepage":"https://trust.attestto.org","bugs":{"url":"https://github.com/Attestto-com/attestto-trust/issues"},"dist":{"shasum":"d5324f7d0d22d16397f59758c664f412a46ae437","tarball":"https://registry.npmjs.org/@attestto/trust/-/trust-1.2.0.tgz","fileCount":1187,"integrity":"sha512-fn8zXQ+uThMMbVWOiOFs2Z2TiU2cdNDXho4LJqpgZgazY1EM8g/vi+kDXtvscnIGanoHQwE20rNzyovNRfZ1eQ==","signatures":[{"sig":"MEUCIQD7G5bU2tiMz0XE7ZSC7awQ4eKwDiQtxRsz9/yYcPdYhwIgea+Ct5RoFM4g3p3OaNKU+nMMW23CQOcAsV0V18etSjg=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":7929300},"main":"index.js","type":"module","types":"./index.d.ts","exports":{".":"./index.js","./ar":"./countries/ar/index.js","./at":"./countries/at/index.js","./be":"./countries/be/index.js","./br":"./countries/br/index.js","./cr":"./countries/cr/index.js","./cz":"./countries/cz/index.js","./de":"./countries/de/index.js","./dk":"./countries/dk/index.js","./ee":"./countries/ee/index.js","./es":"./countries/es/index.js","./fi":"./countries/fi/index.js","./fr":"./countries/fr/index.js","./gr":"./countries/gr/index.js","./hu":"./countries/hu/index.js","./it":"./countries/it/index.js","./lt":"./countries/lt/index.js","./lv":"./countries/lv/index.js","./nl":"./countries/nl/index.js","./no":"./countries/no/index.js","./pe":"./countries/pe/index.js","./pl":"./countries/pl/index.js","./pt":"./countries/pt/index.js","./se":"./countries/se/index.js","./ar/pems/*":"./countries/ar/current/*.pem","./at/pems/*":"./countries/at/current/*.pem","./be/pems/*":"./countries/be/current/*.pem","./br/pems/*":"./countries/br/current/*.pem","./cr/pems/*":"./countries/cr/current/*.pem","./cz/pems/*":"./countries/cz/current/*.pem","./de/pems/*":"./countries/de/current/*.pem","./dk/pems/*":"./countries/dk/current/*.pem","./ee/pems/*":"./countries/ee/current/*.pem","./es/pems/*":"./countries/es/current/*.pem","./fi/pems/*":"./countries/fi/current/*.pem","./fr/pems/*":"./countries/fr/current/*.pem","./gr/pems/*":"./countries/gr/current/*.pem","./hu/pems/*":"./countries/hu/current/*.pem","./it/pems/*":"./countries/it/current/*.pem","./lt/pems/*":"./countries/lt/current/*.pem","./lv/pems/*":"./countries/lv/current/*.pem","./nl/pems/*":"./countries/nl/current/*.pem","./no/pems/*":"./countries/no/current/*.pem","./pe/pems/*":"./countries/pe/current/*.pem","./pl/pems/*":"./countries/pl/current/*.pem","./pt/pems/*":"./countries/pt/current/*.pem","./se/pems/*":"./countries/se/current/*.pem","./anchors/gleif-vlei":"./anchors/gleif-vlei/meta.json"},"funding":"https://github.com/sponsors/Attestto-com","gitHead":"0b4e52f458e92d900133ca954e4acb65394d3595","scripts":{"test":"node --test tests/*.mjs","generate":"node scripts/generate-exports.mjs","prepublishOnly":"npm test"},"_npmUser":{"name":"chongkan","email":"e.chongkan@gmail.com"},"repository":{"url":"git+https://github.com/Attestto-com/attestto-trust.git","type":"git"},"_npmVersion":"11.9.0","description":"Independent public mirror of X.509 trust anchors for national digital signature infrastructures (23 countries across Latin America and the EU/EEA), plus GLEIF vLEI organizational-identity root of trust. Live directory at trust.attestto.org.","directories":{},"_nodeVersion":"25.6.1","_hasShrinkwrap":false,"devDependencies":{"xadesjs":"^2.6.7","node-forge":"^1.4.0","@peculiar/x509":"^2.0.0","@xmldom/xmldom":"^0.8.13","reflect-metadata":"^0.2.2"},"_npmOperationalInternal":{"tmp":"tmp/trust_1.2.0_1784851494284_0.5789650134975268","host":"s3://npm-registry-packages-npm-production"}},"1.3.0":{"name":"@attestto/trust","version":"1.3.0","description":"Independent public mirror of X.509 trust anchors for national digital signature infrastructures (27 countries across Latin America, North America and the EU/EEA), plus GLEIF vLEI organizational-identity root of trust. Live directory at trust.attestto.org.","homepage":"https://trust.attestto.org","funding":"https://github.com/sponsors/Attestto-com","type":"module","main":"index.js","exports":{".":"./index.js","./ar":"./countries/ar/index.js","./ar/pems/*":"./countries/ar/current/*.pem","./at":"./countries/at/index.js","./at/pems/*":"./countries/at/current/*.pem","./be":"./countries/be/index.js","./be/pems/*":"./countries/be/current/*.pem","./br":"./countries/br/index.js","./br/pems/*":"./countries/br/current/*.pem","./cl":"./countries/cl/index.js","./cl/pems/*":"./countries/cl/current/*.pem","./cr":"./countries/cr/index.js","./cr/pems/*":"./countries/cr/current/*.pem","./cz":"./countries/cz/index.js","./cz/pems/*":"./countries/cz/current/*.pem","./de":"./countries/de/index.js","./de/pems/*":"./countries/de/current/*.pem","./dk":"./countries/dk/index.js","./dk/pems/*":"./countries/dk/current/*.pem","./ee":"./countries/ee/index.js","./ee/pems/*":"./countries/ee/current/*.pem","./es":"./countries/es/index.js","./es/pems/*":"./countries/es/current/*.pem","./fi":"./countries/fi/index.js","./fi/pems/*":"./countries/fi/current/*.pem","./fr":"./countries/fr/index.js","./fr/pems/*":"./countries/fr/current/*.pem","./gr":"./countries/gr/index.js","./gr/pems/*":"./countries/gr/current/*.pem","./hu":"./countries/hu/index.js","./hu/pems/*":"./countries/hu/current/*.pem","./it":"./countries/it/index.js","./it/pems/*":"./countries/it/current/*.pem","./lt":"./countries/lt/index.js","./lt/pems/*":"./countries/lt/current/*.pem","./lv":"./countries/lv/index.js","./lv/pems/*":"./countries/lv/current/*.pem","./nl":"./countries/nl/index.js","./nl/pems/*":"./countries/nl/current/*.pem","./no":"./countries/no/index.js","./no/pems/*":"./countries/no/current/*.pem","./pa":"./countries/pa/index.js","./pa/pems/*":"./countries/pa/current/*.pem","./pe":"./countries/pe/index.js","./pe/pems/*":"./countries/pe/current/*.pem","./pl":"./countries/pl/index.js","./pl/pems/*":"./countries/pl/current/*.pem","./pt":"./countries/pt/index.js","./pt/pems/*":"./countries/pt/current/*.pem","./se":"./countries/se/index.js","./se/pems/*":"./countries/se/current/*.pem","./us":"./countries/us/index.js","./us/pems/*":"./countries/us/current/*.pem","./uy":"./countries/uy/index.js","./uy/pems/*":"./countries/uy/current/*.pem","./anchors/gleif-vlei":"./anchors/gleif-vlei/meta.json"},"scripts":{"generate":"node scripts/generate-exports.mjs","test":"node --test tests/*.mjs","prepublishOnly":"npm test"},"keywords":["pki","x509","trust-anchors","eidas","trusted-list","digital-signature","did-pki","gleif","vlei","firma-digital","icp-brasil"],"author":{"name":"Attestto","email":"hello@attestto.com"},"license":"Apache-2.0","repository":{"type":"git","url":"git+https://github.com/Attestto-com/attestto-trust.git"},"devDependencies":{"@peculiar/x509":"^2.0.0","@xmldom/xmldom":"^0.8.13","node-forge":"^1.4.0","reflect-metadata":"^0.2.2","xadesjs":"^2.6.7"},"gitHead":"37810240dada98d7f9c712522734191e23f10aa4","types":"./index.d.ts","_id":"@attestto/trust@1.3.0","bugs":{"url":"https://github.com/Attestto-com/attestto-trust/issues"},"_nodeVersion":"25.6.1","_npmVersion":"11.9.0","dist":{"integrity":"sha512-e2BoJANCjiW3gDrqHXLRiHxMNxeo46hWyFfNRHHK5LmWWDqiyClb4nFd4JR1H+gy3wuBGilwrqRdBhc+ET6MZQ==","shasum":"3c5b01ebccd533f913ece34c89a44c0174cc9e81","tarball":"https://registry.npmjs.org/@attestto/trust/-/trust-1.3.0.tgz","fileCount":1279,"unpackedSize":8468047,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIBrL4I9xmOCDDRd/KPrr4eKXtIGYnCbuyJV8svOAPR7iAiAqIn8q70fbPkXeYiKWWBDFClOMxURY1BNPioj64wey+g=="}]},"_npmUser":{"name":"chongkan","email":"e.chongkan@gmail.com"},"directories":{},"maintainers":[{"name":"chongkan","email":"e.chongkan@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/trust_1.3.0_1784866178960_0.6632694534077441"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-23T11:49:59.165Z","modified":"2026-07-24T04:09:39.455Z","1.0.0":"2026-07-23T11:49:59.464Z","1.1.0":"2026-07-23T20:14:50.808Z","1.2.0":"2026-07-24T00:04:54.537Z","1.3.0":"2026-07-24T04:09:39.278Z"},"bugs":{"url":"https://github.com/Attestto-com/attestto-trust/issues"},"author":{"name":"Attestto","email":"hello@attestto.com"},"license":"Apache-2.0","homepage":"https://trust.attestto.org","keywords":["pki","x509","trust-anchors","eidas","trusted-list","digital-signature","did-pki","gleif","vlei","firma-digital","icp-brasil"],"repository":{"type":"git","url":"git+https://github.com/Attestto-com/attestto-trust.git"},"description":"Independent public mirror of X.509 trust anchors for national digital signature infrastructures (27 countries across Latin America, North America and the EU/EEA), plus GLEIF vLEI organizational-identity root of trust. Live directory at trust.attestto.org.","maintainers":[{"name":"chongkan","email":"e.chongkan@gmail.com"}],"readme":"# attestto-trust\n\n[![Live directory](https://img.shields.io/badge/directory-trust.attestto.org-7B72ED)](https://trust.attestto.org)\n[![npm version](https://img.shields.io/npm/v/@attestto/trust.svg)](https://www.npmjs.com/package/@attestto/trust)\n[![License: Apache-2.0](https://img.shields.io/badge/license-Apache--2.0-blue.svg)](./LICENSE)\n[![Sponsor](https://img.shields.io/badge/sponsor-%E2%9D%A4-db61a2)](https://github.com/sponsors/Attestto-com)\n\n> Independent public mirror of national digital signature trust roots and intermediates. Hash-pinned, version-controlled, git history is the audit trail.\n\n**Browse the live directory at [trust.attestto.org](https://trust.attestto.org)** — every mirrored root and intermediate, per country, with its SHA-256 fingerprint, validity window, key algorithm, CRL/OCSP endpoints, and a one-click `.pem` download.\n\n`@attestto/trust` is a critical trust infrastructure piece for the [Attestto Open](https://attestto.org) ecosystem. Most national PKI repositories are partially broken — wrong content-types, half-deployed HTTPS, mixed-case URL quirks, missing branches, dead links. Every developer integrating a country's digital signature stack hits the same wall. This repo mirrors the binary bytes published by each country's issuing authority as-is, hash-pinned, and version-controlled. The legal source of truth remains the issuing authority in each country. We are not a Certificate Authority — we do not issue, reissue, sign, or vouch for any certificate. **Always verify the SHA-256 against the issuing authority's repository when you can reach it.**\n\n<img width=\"1446\" height=\"1031\" alt=\"image\" src=\"https://github.com/user-attachments/assets/f8e552c4-480e-4855-892f-f38648ef0c4a\" />\n\n\n## Architecture\n\n```mermaid\ngraph LR\n    A[\"National PKI<br/>Authorities\"] -->|publish certs| B[\"attestto-trust<br/>mirror\"]\n    B -->|hash-pinned<br/>version-controlled| C[\"Git history<br/>audit trail\"]\n    B -->|CA chains| D[\"attestto-verify\"]\n    B -->|CA chains| E[\"attestto-desktop\"]\n    B -->|trust roots| F[\"@attestto/verify<br/>web component\"]\n```\n\n## Quick start\n\n### Install\n\n```bash\ngit clone https://github.com/Attestto-com/attestto-trust.git\ncd attestto-trust\npnpm install  # for script dependencies\n```\n\n### Use in your app\n\n**Copy certificates to your trust store:**\n\n```bash\ncp attestto-trust/countries/cr/current/*.pem your-app/trust-store/cr/\n```\n\n**Verify against the bundle:**\n\n```bash\nopenssl verify -CAfile attestto-trust/countries/cr/current/chain.pem your-signed-doc.pem\n```\n\n**Verify a cert's hash:**\n\n```bash\nsha256sum attestto-trust/countries/cr/current/root-ca.pem\n# compare against attestto-trust/countries/cr/current/manifest.json\n```\n\n## Countries\n\n| Country | Package export | Live page | Authority |\n|---|---|---|---|\n| Costa Rica | [`cr/`](countries/cr) | [trust.attestto.org/cr](https://trust.attestto.org/cr) | BCCR / SINPE / MICITT Firma Digital |\n| Brazil | [`br/`](countries/br) | [/br](https://trust.attestto.org/br) | ITI — ICP-Brasil |\n| Argentina | [`ar/`](countries/ar) | [/ar](https://trust.attestto.org/ar) | AC Raíz de la República Argentina |\n| Spain | [`es/`](countries/es) | [/es](https://trust.attestto.org/es) | FNMT-RCM (Ceres) |\n| Austria | [`at/`](countries/at) | [/at](https://trust.attestto.org/at) | RTR / Telekom-Control-Kommission (TKK) eIDAS Trusted List |\n| Belgium | [`be/`](countries/be) | [/be](https://trust.attestto.org/be) | FPS Economy (Federal Public Service Economy) eIDAS Trusted List |\n| Czech Republic | [`cz/`](countries/cz) | [/cz](https://trust.attestto.org/cz) | DIA (Digitální a informační agentura) eIDAS Trusted List |\n| Denmark | [`dk/`](countries/dk) | [/dk](https://trust.attestto.org/dk) | Digitaliseringsstyrelsen (Danish Agency for Digital Government) eIDAS Trusted List |\n| Estonia | [`ee/`](countries/ee) | [/ee](https://trust.attestto.org/ee) | RIA — SK ID Solutions / Zetes (eIDAS) |\n| Finland | [`fi/`](countries/fi) | [/fi](https://trust.attestto.org/fi) | Traficom (Liikenne- ja viestintävirasto) eIDAS Trusted List / DVV FINeID |\n| France | [`fr/`](countries/fr) | [/fr](https://trust.attestto.org/fr) | ANSSI eIDAS Trusted List (~20 QTSPs) |\n| Germany | [`de/`](countries/de) | [/de](https://trust.attestto.org/de) | Bundesnetzagentur (BNetzA) eIDAS Trusted List |\n| Greece | [`gr/`](countries/gr) | [/gr](https://trust.attestto.org/gr) | EETT (Hellenic Telecommunications and Post Commission) eIDAS Trusted List |\n| Hungary | [`hu/`](countries/hu) | [/hu](https://trust.attestto.org/hu) | NMHH (National Media and Infocommunications Authority) eIDAS Trusted List |\n| Italy | [`it/`](countries/it) | [/it](https://trust.attestto.org/it) | AgID eIDAS Trusted List (~25 QTSPs) + CIE national eID |\n| Latvia | [`lv/`](countries/lv) | [/lv](https://trust.attestto.org/lv) | DDUK (Digitālās drošības uzraudzības komiteja) eIDAS Trusted List / LVRTC eParaksts |\n| Lithuania | [`lt/`](countries/lt) | [/lt](https://trust.attestto.org/lt) | RRT (Ryšių reguliavimo tarnyba) eIDAS Trusted List |\n| Netherlands | [`nl/`](countries/nl) | [/nl](https://trust.attestto.org/nl) | RDI (Rijksinspectie Digitale Infrastructuur) eIDAS Trusted List |\n| Norway | [`no/`](countries/no) | [/no](https://trust.attestto.org/no) | Nkom (Nasjonal kommunikasjonsmyndighet) eIDAS Trusted List |\n| Peru | [`pe/`](countries/pe) | [/pe](https://trust.attestto.org/pe) | INDECOPI — IOFE (RENIEC, ONPE, ECERNEP) |\n| Poland | [`pl/`](countries/pl) | [/pl](https://trust.attestto.org/pl) | NCCert (Narodowe Centrum Certyfikacji) / NBP eIDAS Trusted List |\n| Portugal | [`pt/`](countries/pt) | [/pt](https://trust.attestto.org/pt) | GNS — Autoridade Credenciadora / SCEE eIDAS Trusted List |\n| Sweden | [`se/`](countries/se) | [/se](https://trust.attestto.org/se) | PTS (Post- och telestyrelsen) eIDAS Trusted List |\n\nMore countries are staged and land after a per-country promotion review: Mexico, Colombia, Chile, Ecuador, Uruguay, Panama, and other European trusted lists. Italy's full qualified-signature list (229 accredited-QTSP CAs), Germany's (101 accredited-QTSP CAs), Greece's (105 accredited-QTSP CAs), France's (79 accredited-QTSP CAs), the Netherlands' (30 accredited-QTSP CAs), Belgium's (52 accredited-QTSP CAs), Austria's (39 accredited-QTSP CAs), Portugal's (30 accredited-QTSP CAs), Poland's (29 accredited-QTSP CAs), Hungary's (62 accredited-QTSP CAs), the Czech Republic's (34 accredited-QTSP CAs), Norway's (26 accredited-QTSP CAs), Finland's (12 DVV/VRK FINeID CAs), Lithuania's (11 accredited-QTSP CAs), Sweden's (8 accredited-QTSP CAs), Denmark's (5 accredited-QTSP CAs), and Latvia's (5 accredited-QTSP CAs) are now live, promoted wholesale after verifying each national Trusted List's XAdES signature through the EU LOTL chain of trust (see `scripts/monitors/verify-eu-tsl.mjs`).\n\n## Global / organizational anchors\n\nBeyond national PKI, the directory mirrors global organizational-identity roots under `anchors/`.\nThe first is **GLEIF vLEI** (`anchors/gleif-vlei/`), the GLEIF root of trust and its authorized\nQualified vLEI Issuers, hash-pinned and version-controlled. vLEI is KERI/ACDC (not X.509), pinned\nas an AID key-state rather than a CA certificate. We mirror what GLEIF publishes and do not\nissue or vouch for any credential. See [trust.attestto.org/gleif](https://trust.attestto.org/gleif).\n\n## Key concepts\n\n### Certificate manifest\n\nEach country has a `manifest.json` listing all certificates with their hashes and metadata:\n\n```json\n[\n  {\n    \"filename\": \"root-ca.pem\",\n    \"sha256\": \"a1b2c3...\",\n    \"subject\": \"CN=CA RAIZ NACIONAL - COSTA RICA v2, ...\",\n    \"issuer\": \"CN=CA RAIZ NACIONAL - COSTA RICA v2, ...\",\n    \"validFrom\": \"2015-07-09\",\n    \"validTo\": \"2035-07-09\",\n    \"role\": \"root\"\n  },\n  ...\n]\n```\n\nUse this to audit what's installed and verify against the issuing authority's published repository.\n\n### Audit trail\n\nEvery cert added, rotated, or retired is a git commit with a clear message describing what changed and why. The full git history is the source of truth for the certificate lifecycle.\n\n```bash\ngit log --follow countries/cr/current/\n```\n\n## Repository layout\n\n```\nattestto-trust/\n├── README.md                      ← you are here\n├── scripts/\n│   ├── extract-chain-from-pdf.mjs ← extract certs from signed PDFs\n│   ├── generate-exports.mjs       ← regenerate JS/TS exports from PEM files\n│   └── refresh-manifest.mjs       ← regenerate manifest.json + chain.pem\n├── countries/\n│   └── <iso2>/\n│       ├── README.md              ← country-specific notes + CA hierarchy\n│       ├── current/               ← certs currently active\n│       │   ├── *.pem\n│       │   ├── chain.pem          ← all-in-one bundle\n│       │   └── manifest.json      ← sha256, subject, issuer, valid dates\n│       ├── archive/               ← superseded certs, kept forever\n│       └── samples/               ← signed docs (when redistributable)\n└── .github/workflows/verify.yml   ← CI: verify all cert hashes on every push\n```\n\n## Using the certificates\n\n### Drop into your trust store\n\n```bash\ngit clone https://github.com/Attestto-com/attestto-trust.git\ncp attestto-trust/countries/cr/current/*.pem your-app/trust-store/cr/\n```\n\n### Verify against the bundle\n\n```bash\nopenssl verify -CAfile attestto-trust/countries/cr/current/chain.pem some-signer.pem\n```\n\n### Verify a cert's hash before using it\n\n```bash\nsha256sum attestto-trust/countries/cr/current/root-ca.pem\n# compare against attestto-trust/countries/cr/current/manifest.json sha256 field\n```\n\n## Updating an existing country\n\nWhen the issuing authority rotates a cert (root or intermediate):\n\n1. Move the old PEM from `countries/<iso2>/current/` into `countries/<iso2>/archive/<year>/`\n2. Drop the new PEM into `countries/<iso2>/current/`\n3. Run `node scripts/refresh-manifest.mjs` — rebuilds `manifest.json` + `chain.pem`\n4. Run `node scripts/generate-exports.mjs` — regenerates JS exports + `.d.ts` types\n5. Commit with a clear message: *\"cr: rotate CA SINPE PERSONA FISICA v2 → v3, expires 2032\"*\n6. Push\n\n## Adding a country\n\n```bash\nmkdir -p countries/<iso2>/{current,archive,samples}\n\n# Extract intermediates from any signed sample document for that country\nnode scripts/extract-chain-from-pdf.mjs ~/Downloads/some-signed.pdf /tmp/out\n\n# Inspect, then move the relevant intermediates into countries/<iso2>/current/\ncp /tmp/out/*.pem countries/<iso2>/current/\n\n# Generate manifest + chain.pem + JS exports\nnode scripts/refresh-manifest.mjs\nnode scripts/generate-exports.mjs\n\n# Write country-specific notes + CA hierarchy diagram\nvi countries/<iso2>/README.md\n\n# Commit\ngit add countries/<iso2> index.js\ngit commit -m \"<iso2>: initial trust mirror — N certs\"\n```\n\nUpdate the country table in this README and open a pull request. CI will verify all hashes.\n\n## Publishing a release\n\nThe package is published to npm as [`@attestto/trust`](https://www.npmjs.com/package/@attestto/trust). Publish whenever the certificate set changes (a country added, or a cert rotated).\n\n1. Land the cert changes on `main` and confirm CI is green.\n2. Bump the version so the registry and git stay in lockstep — patch for a cert rotation, minor for a new country:\n   ```bash\n   npm version patch   # or: npm version minor\n   ```\n3. Publish (the scoped package requires public access; `prepublishOnly` runs the test suite first):\n   ```bash\n   npm publish --access public\n   ```\n4. Push the version commit and tag:\n   ```bash\n   git push --follow-tags\n   ```\n\nNever republish an existing version — bump first. The `files` allow-list in `package.json` ships only the JS exports, PEMs, and manifests (no scripts, samples, or archive).\n\n## Limitations\n\nWe are **not** a Certificate Authority — we don't issue, reissue, sign, or vouch for any certificate. We are **not** an OCSP/CRL responder — revocation is time-sensitive, get it from the issuing authority directly. We deliberately don't mirror CRLs because a stale CRL is worse than none. If our mirror disagrees with the issuing authority's published repository, the authoritative source wins — open an issue and we'll fix it.\n\n## Ecosystem\n\n| Repo | Role | Relationship |\n|---|---|---|\n| `attestto-verify` | Web verification component | Uses these trust roots for signature verification |\n| `attestto-desktop` | Desktop signer/verifier | Verifies documents against these roots |\n| `attestto-anchor` | Solana hash anchoring | Anchors identity & signature metadata |\n| `cr-vc-schemas` | Costa Rica credential schemas | Defines the vLEI/Firma Digital signing mechanism |\n\n## Build with an LLM\n\nThis repo ships a [`llms.txt`](./llms.txt) context file — a machine-readable summary of the API, data structures, and integration patterns designed to be read by AI coding assistants.\n\n### Recommended setup\n\nUse the [`attestto-dev-mcp`](../attestto-dev-mcp) server to give your LLM active access to the ecosystem:\n\n```bash\ncd ../attestto-dev-mcp\nnpm install && npm run build\n```\n\nThen add it to your Claude / Cursor / Windsurf config and ask:\n\n> *\"Explore the Attestto ecosystem and help me set up [this component]\"*\n\n### Which model?\n\nWe recommend **[Claude](https://claude.ai) Pro** (5× usage vs free) or higher. Long context and strong TypeScript reasoning handle this codebase well. The MCP server works with any LLM that supports tool use.\n\n> **Quick start:** Ask your LLM to read `llms.txt` in this repo, then describe what you want to build. It will find the right archetype, generate boilerplate, and walk you through the first run.\n\n## Contributing\n\nWe welcome contributions. To add a country, open a PR following the layout above. CI will verify all certificate hashes automatically. For questions about trust roots or PKI hierarchy, open an issue with a reference to the issuing authority's published repository.\n\n## License\n\nThe certificates are public-key X.509 published by national issuing authorities; freely redistributable. Scripts and documentation are Apache-2.0. See [LICENSE](./LICENSE).\n\n---\n\n**Provenance:** Maintained by [Attestto](https://attestto.org) as part of public-good work on national digital identity infrastructure. See <https://attestto.org/ark>.\n\nIf you find a cert that's missing, expired, or mishashed, open an issue with a sample signed document we can extract from, and we'll get it in.\n","readmeFilename":"README.md"}