Issue and use a STIR/SHAKEN delegate certificate so a downstream enterprise can sign its own PASSporT.
domain: transnexus.com · 5 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗
Steps
As the TN service provider, request an SPC token from the STI-PA with the CA object set to true to become a Subordinate CA.
Use that SPC token to obtain a Subordinate CA certificate from an STI-CA (its sole purpose is issuing delegate certs, not signing calls directly).
Issue a delegate certificate to the downstream VoIP Entity, scoped to the specific telephone numbers you assigned it.
The VoIP Entity signs a base PASSporT (or RCD PASSporT for Rich Call Data) with the delegate cert — never a SHAKEN PASSporT.
Terminating providers verify the cert chain (delegate to Subordinate CA to root) and confirm the call's number is inside the delegate cert's TNAuthList scope.
Known gotchas
A delegate certificate cannot be used to sign a full SHAKEN PASSporT — only base/RCD PASSporTs.
This mechanism specifically solves the 'customer of customer' problem (e.g. toll-free Resp Org resellers) where the signer never received the number directly from a carrier.
Delegate cert support requires STI-PA/STI-GA policy enablement — confirm your STI-CA and STI-PA both support the subordinate-CA workflow before building against it.
Give your agent this knowledge — and 15,500+ more routes
One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus:
claude mcp add --transport http waymark https://mcp.waymark.network/mcp
Need this verified for your stack — or a route we don't have yet?