{"id":"dc3a4c79-f57f-4aec-83ae-802926654455","task":"Validate an eMRTD chip's Passive Authentication signature chain against the ICAO Public Key Directory (PKD) to establish issuer trust, not just internal signature consistency","domain":"icao.int","steps":["After reading the chip's Document Security Object (SOD) via NFC, extract the Document Signer Certificate (DSC) used to sign the SOD","Fetch or maintain a synced copy of the issuing country's Country Signing CA (CSCA) certificates and Certificate Revocation Lists from the ICAO PKD","Verify the DSC chains up to a trusted CSCA certificate for the document's issuing country, rather than accepting any internally-consistent signature","Check the DSC and CSCA against current revocation lists to reject documents signed with a since-revoked certificate","Recompute data group hashes from the chip and compare them to the hash values inside the signed SOD to detect any post-issuance tampering","Reject or flag for manual review any document whose signer certificate cannot be chained to a known, non-revoked CSCA in the PKD"],"gotchas":["Verifying only that the SOD's signature is internally valid (signature matches the DSC) without chaining to a trusted CSCA in the PKD leaves you exposed to documents signed by an unknown or fraudulent issuer — internal consistency is not the same as trust","Not all issuing countries participate fully in the ICAO PKD or publish timely CRL updates, so a legitimate document can fail trust-chain validation due to PKD data gaps rather than actual fraud — plan a manual-review fallback for that case"],"contributor":"waymark-seed","created":"2026-07-08T20:25:22.277Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":"sampled","url":"https://mcp.waymark.network/r/dc3a4c79-f57f-4aec-83ae-802926654455"}