This package contains documentation and Bash shell scripts needed to use the KERIpy command line tool (kli) to
participate as a GLEIF Authorized Representative (GAR) as a member of the GLEIF External Autonomic Identifier (AID) or
the GLEIF Internal Autonomic Identifier (AID)
This repository contains documentation in the ./docs directory and Bash shell scripts in the ./scripts directory. The
scripts make it easy to use the KERI command line tool kli to perform all functions required of a GAR. It utilizes the KERI
docker image gleif/keri:1.1.44, plus a few backported kli fixes layered on by internal/Dockerfile and
external/Dockerfile, with mounts to local directories to minimize the requirements on the local system.
The steps needed to bootstrap your system are described in Getting Started. After following the steps described in that document you will have a KERI datastore and keystore encrypted using a randomly generated passcode that is automatically stored in your Mac keychain.
From there you will be ready to join and participate in a Group Multisig AID as described in Creating Group AID.
The following table contains reference matertial and repository links for the vLEI schema, the KERI protocol and ACDC credentials, all foundational concepts and technologies for GLEIF's vLEI ecosystem:
| Acronym | Full Name of Deliverable | Link to Deliverable | Lead Authors | Status / Notes |
|---|---|---|---|---|
| KERI | Key Event Receipt Infrastructure (KERI) | ToIP KERI Spec | Samuel Smith | Specification |
| vLEI EGF | vLEI Ecosystem Governance Framework | vLEI EGF | Karla McKenna / Drummond Reed | Published |
| vLEI Schema | The published JSON schema for all vLEI credentials | vLEI Schema | Phil Feaihreller / Kevin Griffin | Published |
| SAID | Self-Addressing Identifiers | IETF SAID Draft | Samuel Smith | Subsumed by spec |
| ACDC | Authentic Chained Data Containers | ToIP ACDC Spec | Samuel Smith | Specification |
| OOBI | Out-Of-Band-Introduction | IETF OOBI Draft | Sam Smith | Subsumed by spec |
| CESR | Composable Event Streaming Representation | IETF CESR Draft | Samuel Smith | Specification |
| CESR Proof | CESR Proof Signatures | IETF CESR Proof Signatures Draft | Phil Feairheller | Subsumed by spec |
| PTEL | Public Transaction Event Logs | IETF PTEL Draft | Phil Feairheller | Subsumed by spec |
There are several scripts located in the scripts directory that are described specifically in any flow documentation
but are provided as utilities that can be helpful for GAR controllers while participanting in the vLEI ecosystem. The
following table describes the scripts, all of which can be used any time after the steps described in Getting Started
| Script | Purpose |
|---|---|
./scripts/status.sh |
AID status script that can be used to inspect key state of any local AID |
./scripts/contacts.sh |
Script to list any contacts locally resolved through OOBI exchange. Indicates Authentication status |
./scripts/delegate-confirm-preflight.sh |
External only. Read-only check before approving a QVI rotation: QVI key state held locally, escrows, witness reachability, current anchor.json |
./scripts/challenge-members.sh |
Challenge several contacts (a QVI's QARs, the other GARs) one after another with your member AID and show their Authenticated state |
./scripts/respond-for-group.sh |
Answer a challenge that was addressed to the group AID: prints the member alias, AID and OOBI the challenger needs, then responds with your member AID |
./scripts/sent-exns.sh |
List the exchange messages your AIDs sent (IPEX grants and more) with the credential, its registry state, which members signed, who delivered it, and the admit if one came back; --poll fetches replies first |
A group multisig AID can verify a challenge but cannot answer one with the kli this repository runs, so all
challenge scripts sign and verify with your member AID. What to do when someone challenges the GLEIF External or
Internal AID, how to challenge a QVI, and why the limitation exists are described in
Challenge/response and multisig AIDs.
GEDA: GLEIF External Delegated AID GIDA: GLEIF Internal Delegated AID QVI: Qualified vLEI Issuer LE: Legal Entity GAR: GLEIF Authorized Representative QAR: Qualified vLEI Issuer Authorized Representative LAR: Legal Entity Authorized Representative ECR: Engagement Context Role Person