Interface IssuerKeyRegistry

All Known Implementing Classes:
MapIssuerKeyRegistry

public interface IssuerKeyRegistry
Resolves the public key an issuer is known to sign with.

Why verification needs this

A voucher carries an issuer id and an issuer_pubkey tag, and verification used to check the signature against that embedded key (audit H-14). A signature that verifies under a key the signer chose proves only that whoever built the voucher held the matching private key, which the attacker does: generate a keypair, put the merchant's issuer id in the voucher, sign with your own key, and offline verification passes. The voucher was, in effect, self-certifying.

A signature is only evidence when it verifies under a key you already trust. This port is where that key comes from. Implementations range from a configured map for a single merchant to a lookup against a merchant directory.

  • Method Summary

    Modifier and Type
    Method
    Description
    publicKeyFor(String issuerId)
    The public key registered for an issuer.
  • Method Details

    • publicKeyFor

      Optional<String> publicKeyFor(String issuerId)
      The public key registered for an issuer.
      Parameters:
      issuerId - the issuer identifier claimed by a voucher
      Returns:
      the hex-encoded public key, or empty when the issuer is unknown