docs: record official FURS test evidence - #7
Draft
Starfiniti wants to merge 1 commit into
Draft
Conversation
Signed-off-by: Dejan Kletečki <120020919+Starfiniti@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changed
Records the first official FURS test-certificate evidence without committing certificate material, passwords, tax identities, raw fiscal payloads, or JWS tokens.
Compliance
Requirements: FURS-TLS-001/002, FURS-JWS-002, FURS-SCHEMA-001, FURS-SEC-001/002, FURS-CERT-001, FURS-REL-001.
Official sources reviewed on 13 August 2026: FURS technical documentation v3.2, current official Draft-04 schema, current FURS developer certificate links, and current SIGOV-CA/SI-TRUST chain. The changed SPOT online-retail digest remains frozen and was not used for these protocol tests.
Evidence and security
Protected redacted evidence SHA-256 values are recorded in compliance/PHASE_1_STATUS.md. Raw credentials, request/response tokens, full payloads, and tax identities remain outside the repository. The PKCS#12 and passphrase are separate, outside Git and synchronised folders, with Windows ACL access restricted to the current user and SYSTEM.
Stored records, compatibility, and rollback
No database, API, runtime behavior, migration, or stored fiscal record changes. Rollback is a documentation-only revert; protected evidence remains preserved independently.
Checks