Skip to content

Add ComputeID AgentPassport TRACE adapter (community tier) - #176

Open
trustedaicompute-ops wants to merge 5 commits into
agentrust-io:mainfrom
trustedaicompute-ops:main
Open

Add ComputeID AgentPassport TRACE adapter (community tier)#176
trustedaicompute-ops wants to merge 5 commits into
agentrust-io:mainfrom
trustedaicompute-ops:main

Conversation

@trustedaicompute-ops

Copy link
Copy Markdown

Adds a community-tier integration mapping ComputeID AgentPassport /verify evidence into a TRACE v0.2-shaped record, via the third-party-control-plane / external-evidence-source path.

Honest, current result: FAIL at Level 0, 4 of 8 checks fail (missing cnf/proof-of-possession binding, and no policy/appraisal fields, since ComputeID is an identity-issuance system, not an execution-attestation runtime). No trace_conformance_level is declared for this reason. Full result and reasoning in CONFORMANCE.md.

Includes real, reproducible evidence: a genuine, unmodified ComputeID /verify response, an offline verifier requiring zero network calls, and a separate audit-chain integrity tool. The two hardest cryptographic checks (classical RSA-SHA256 and post-quantum ML-DSA-65 signature verification) pass and were adversarially tested (correctly fail against a fake CA certificate).

Will open a separate spec issue on trace-spec for the cnf/proof-of-possession gap and its relation to our existing DPoP support, as requested.

Added integration configuration for ComputeID AgentPassport TRACE Adapter.
Added README for ComputeID AgentPassport TRACE Adapter, detailing its functionality, limitations, usage instructions, and verification process.
Added TRACE conformance result details, including failures and explanations.
Add adapter code and CA certificate
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant