Skip to content

OCSP failures don't specify claim signature box in url field #2726

Description

@sherifhanna-google

Component

c2pa-rs

If Other, please specify

No response

Version

0.91.0-dev

Platform

Linux

What happened?

URLs in status codes are supposed to indicate the JUMBF structure (signature, assertion, claim etc.) that the success/failure corresponds to. However, OCSP failures currently do not show the claim signature box as the URL, as required by the spec.

Correct status code url value:

          {
            "code":"signingCredential.trusted",
            "url":"self#jumbf=/c2pa/urn:c2pa:127c8bf2-c162-4e1c-8665-85e048472559/c2pa.signature",
            "explanation":"signing certificate trusted, found in [system_anchors] trust anchors"
          }

Current behavior for OCSP failure status code - notice the contents of the url field:

          {
            "code":"signingCredential.ocsp.revoked",
            "url":"OCSP_RESPONSE",
            "explanation":"certificate revoked"
          }

What did you expect to happen?

The url field for the signingCredential.ocsp.revoked status code to contain the claim signature JUMBF box URL.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions