verify

open suspend override fun verify(chain: List<X509Cert>, atTime: Instant, validateCaValidity: Boolean, docType: String?): TrustResult

Checks if an entity identifying itself via a certificate chain is trusted for a specific ISO mdoc document type.

The following checks are performed:

  • A matching trust point is located by comparing its Subject Key Identifier (extension 2.5.29.14) with the Authority Key Identifier (extension 2.5.29.35) of the certificate issued under it (or by matching the certificate itself if a single certificate is supplied).

  • The certification path from the leaf certificate to the root certificate is validated according to RFC 5280:

  • The digital signature on each certificate in the chain is verified using the public key of the issuer.

  • The root certificate signature is verified to be self-signed.

  • The leaf certificate validity period is verified against atTime. If validateCaValidity is true, intermediate and root CA validity periods are also checked.

  • The leaf certificate's Key Usage extension is verified to contain digitalSignature.

  • In accordance with ISO/IEC 18013-5 Second Edition clause 12.8.3, if verifying an issuer certificate chain (such as when docType is specified or trust is established via a VICAL):

  • If the root (IACA) certificate specifies a countryName (C), the leaf certificate must have the same countryName.

  • If both the root (IACA) and leaf certificate specify a stateOrProvinceName (ST), they must match.

  • In accordance with ISO/IEC 18013-5 Second Edition clause 12.8.1:

  • If docType is provided and trust is established via a VICAL, docType must be in the list of authorized document types for that certificate.

Return

a TrustResult instance with the verdict.

Parameters

chain

the certificate chain without the self-signed root certificate.

atTime

the point in time to check validity for.

validateCaValidity

whether to validate validity intervals for CA certificates in the chain.

docType

the ISO mdoc document type (e.g. org.iso.18013.5.1.mDL), if validating authorization against a VICAL.