Conformance Matrix
Specification Conformance Matrix
Section titled “Specification Conformance Matrix”1.2 Specification Conformance Matrix
Section titled “1.2 Specification Conformance Matrix”The following matrix documents the exact normative status of each specification, its implementation level within resolver-core, the specific profiles tested, and known boundaries or exclusions.
| Specification | Formal Normative Status | DID.is Level | Tested Profiles / Cryptosuites | Known Boundaries & Hard Exclusions | Source Reference |
|---|---|---|---|---|---|
| W3C DID Core 1.0 | W3C Recommendation (2022-07-19) | Full | Verification relationships, document syntax, metadata | @context is validated against static catalog; dynamic JSON-LD expansion is disabled. |
did_syntax.rs |
| W3C DID Core 1.1 | W3C CR Snapshot (2024-04-11) | Full | Context v1.1, URL dereferencing, representations | Representation metadata profiles validated against deterministic JSON schema. | did_syntax.rs |
| W3C DID Resolution v1.0 | W3C CR Draft / CCG Draft | Full | Resolution, URL dereferencing, content negotiation | Strict RFC 9457 error mapping; secondary resource dereferencing supported. | server.rs |
| did:key Method v0.9 | W3C CCG Community Specification | Full | ed25519-pub (0xed), p256-pub (0x1200), secp256k1-pub (0xe7), x25519-pub (0xec) |
P-384, P-521, BLS12-381 G2, and RSA codecs are recognized but cannot verify signatures. | methods/key.rs |
| did:jwk Method | DIF Community Specification | Full | JSON Web Key 2020, RFC 7638 thumbprints | Maximum encoded length 4,096 chars; private key members (d, p, q, etc.) strictly rejected. |
methods/jwk.rs |
| did:web Method | W3C CCG Community Specification | Full | /.well-known/did.json, /<path>/did.json |
IP literals, userinfo, and dot segments rejected; egress pinned to public IPs; ID match enforced. | methods/web.rs |
| did:webvh 1.0 | DIF Community Specification | Full | did:webvh:1.0, SHA-256 SCID, did.jsonl |
Maximum 2,000 log entries; 4 MiB log cap; 1 MiB witness cap; eddsa-jcs-2022 proofs required. |
methods/webvh.rs |
| W3C VC Data Model 2.0 | W3C Recommendation (2024-05-16) | Full | Data Integrity, validFrom/validUntil, @context v2 |
Multi-subject credentials rejected in legacy profiles; single subject enforced. | vc.rs |
| W3C VC Data Model 1.1 | W3C Recommendation (2019-11-19) | Full | Legacy VC-JWT (vc claim), issuanceDate/expirationDate |
Strict claim mirroring (sub == vc.credentialSubject.id, iss == vc.issuer). |
vc.rs |
| W3C VC Data Integrity 1.0 | W3C Recommendation (2024-05-16) | Full | JCS-based Data Integrity proof verification | Proof chains (previousProof) unsupported; requires unchained proofs. |
data_integrity.rs |
| Data Integrity EdDSA Suites v1.0 | W3C Recommendation (2024-05-16) | Full | eddsa-jcs-2022 (Ed25519) |
Strict RFC 8032 signature verification (verify_strict); non-canonical signatures rejected. |
data_integrity.rs |
| Data Integrity ECDSA Suites v1.0 | W3C Recommendation (2024-05-16) | Partial | ecdsa-jcs-2019 with NIST P-256 |
secp256k1 under ecdsa-jcs-2019 is explicitly rejected (P-256 only). |
data_integrity.rs |
| W3C Bitstring Status List v1.0 | W3C Recommendation (2024) | Full | BitstringStatusListEntry, multibase base64url ('u'), single-bit revocation/suspension |
Minimum 131,072 bits; 16 MiB decompression limit; multi-bit / custom message unsupported. | vc.rs |
| StatusList2021 | W3C CCG Community Specification | Full | StatusList2021Entry, legacy gzip base64 |
Single-bit revocation/suspension only; same-issuer authorization enforced. | vc.rs |
| IETF RFC 8785 (JCS) | IETF Standards Track (2020-06) | Full | Profile rfc8785-binary64-v1, UTF-16 code units, ryu-js float |
Reject duplicate keys at parser level; IEEE-754 binary64 integer rounding beyond $2^{53}$. | jcs.rs |
| IETF RFC 7515 (JWS) | IETF Standards Track (2015-05) | Full | Compact serialization, EdDSA, ES256, ES256K | alg: none rejected; unencoded payloads (b64: false) rejected; crit headers rejected. |
jws.rs |
| IETF RFC 7519 (JWT) | IETF Standards Track (2015-05) | Full | NumericDate temporal validation, audience verification | Fractional seconds in nbf/exp supported without float-truncation artifacts. |
jwt_profile_regressions.rs |
| IETF RFC 7638 (JWK Thumbprint) | IETF Standards Track (2015-09) | Full | SHA-256 base64url thumbprints over required members | Evaluated for EC (P-256, secp256k1) and OKP (Ed25519, X25519) keys. | crypto.rs |
| IETF RFC 9457 (Problem Details) | IETF Standards Track (2023-07) | Full | application/problem+json standard error envelope |
Emits type, title, status, detail, instance, code, resolution_metadata. |
error.rs |
| DIF Well Known DID Config | DIF Community Specification | Full | DomainLinkageCredential (JWT & Data Integrity) |
Must be fetched from origin root; iss == sub == did and origin matching enforced. |
domain_linkage.rs |
| LF A2A Protocol v1.0.0 | Linux Foundation Open Spec | Full | /.well-known/agent-card.json, detached JWS, jku |
Maximum 512 KiB card size; jku fetch bounded to 128 KiB; interface validation. |
a2a.rs |
| Model Context Protocol (MCP) | Anthropic Open Specification | Full | Streamable HTTP (2026-07-28 stateless & 2025-11-25 legacy) |
JCS SHA-256 tool definition/schema hashes; heuristic risk classification; Unicode guards. | mcp.rs |
| DID.is Delegation Receipt v1 | Experimental (DID.is Proprietary) | Full | didis-delegation+jwt, SHA-256 prf chain, attenuation |
Maximum chain depth 8; acyclicity DAG enforced; monotonic capability attenuation. | delegation.rs |
| W3C RDF Dataset Canonicalization | W3C Recommendation | Unsupported | eddsa-rdfc-2022, ecdsa-rdfc-2019, Ed25519Signature2020 |
Explicitly rejected as UNSUPPORTED. Engine deliberately does not evaluate RDF graph canonicalization. |
data_integrity.rs |
| W3C Selective Disclosure | Working Draft | Unsupported | ecdsa-sd-2023, bbs-2023 |
Explicitly rejected as UNSUPPORTED. |
data_integrity.rs |