Skip to content

A reader must see who declared the data, not just who sealed it #126

Description

@LKSNDRTMLKV

The problem

A seal proves a document came from whoever holds the certificate. It carries no statement about scope — nothing distinguishes "we vouch for this content" from "we transmitted this intact". It looks identical either way.

So if a passport prominently shows a seal from the node operator, and the party that actually declared the data is only discoverable by digging, a reader will reasonably conclude the node vouches for the content. Regardless of what the regulation says about where the obligation sits, and regardless of what we intend.

Meaning that does not travel with the document does not exist.

What already exists

ResponsibleOperator, operator_identifier, the manufacturer block, the facility snapshot, and the transfer-of-responsibility machinery. The pieces are there.

What is missing

Evidence that a reader — human or machine — can answer "who declared this?" as easily as "who sealed this?". Right now nobody has checked, and it is the difference between a design intention and a property of the artefact.

Scope

  • Establish whether the declaring party is unambiguous in each served view: public, restricted, conformity, individual.
  • Where it is not, make it so. The public view is the one that matters most and is the most likely to be missing it.
  • A test that fails if a passport can be served with a seal but no legible declarer.

Why it matters more than it looks

This is what makes "we carry the data, we do not author it" a fact about the passport rather than a position held internally. If a partner or an authority cannot tell the two roles apart, the distinction is not real no matter how the contracts read.

Metadata

Metadata

Assignees

No one assigned

    Labels

    complianceRegulatory/compliance correctness issuesecuritySecurity-relevant issue

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions