Component
c2pa-rs
If Other, please specify
No response
Version
0.91.0-dev
Platform
Linux
What happened?
URLs in status codes are supposed to indicate the JUMBF structure (signature, assertion, claim etc.) that the success/failure corresponds to. However, OCSP failures currently do not show the claim signature box as the URL, as required by the spec.
Correct status code url value:
{
"code":"signingCredential.trusted",
"url":"self#jumbf=/c2pa/urn:c2pa:127c8bf2-c162-4e1c-8665-85e048472559/c2pa.signature",
"explanation":"signing certificate trusted, found in [system_anchors] trust anchors"
}
Current behavior for OCSP failure status code - notice the contents of the url field:
{
"code":"signingCredential.ocsp.revoked",
"url":"OCSP_RESPONSE",
"explanation":"certificate revoked"
}
What did you expect to happen?
The url field for the signingCredential.ocsp.revoked status code to contain the claim signature JUMBF box URL.
Component
c2pa-rs
If Other, please specify
No response
Version
0.91.0-dev
Platform
Linux
What happened?
URLs in status codes are supposed to indicate the JUMBF structure (signature, assertion, claim etc.) that the success/failure corresponds to. However, OCSP failures currently do not show the claim signature box as the URL, as required by the spec.
Correct status code
urlvalue:Current behavior for OCSP failure status code - notice the contents of the
urlfield:What did you expect to happen?
The
urlfield for thesigningCredential.ocsp.revokedstatus code to contain the claim signature JUMBF box URL.