Skip to content

docs: record official FURS test evidence - #7

Draft
Starfiniti wants to merge 1 commit into
mainfrom
agent/record-furs-test-evidence
Draft

docs: record official FURS test evidence#7
Starfiniti wants to merge 1 commit into
mainfrom
agent/record-furs-test-evidence

Conversation

@Starfiniti

Copy link
Copy Markdown
Owner

What changed

Records the first official FURS test-certificate evidence without committing certificate material, passwords, tax identities, raw fiscal payloads, or JWS tokens.

  • records successful strict TLS 1.3 Echo evidence
  • records official missing/wrong-client rejection evidence
  • records an RS256/chain/signer-pin/schema/MessageID-verified signed S005 rejection
  • updates P0/P1/P7 status and the production checklist
  • corrects stale container-evidence status after the successful GitHub image scan

Compliance

Requirements: FURS-TLS-001/002, FURS-JWS-002, FURS-SCHEMA-001, FURS-SEC-001/002, FURS-CERT-001, FURS-REL-001.

Official sources reviewed on 13 August 2026: FURS technical documentation v3.2, current official Draft-04 schema, current FURS developer certificate links, and current SIGOV-CA/SI-TRUST chain. The changed SPOT online-retail digest remains frozen and was not used for these protocol tests.

Evidence and security

Protected redacted evidence SHA-256 values are recorded in compliance/PHASE_1_STATUS.md. Raw credentials, request/response tokens, full payloads, and tax identities remain outside the repository. The PKCS#12 and passphrase are separate, outside Git and synchronised folders, with Windows ACL access restricted to the current user and SYSTEM.

Stored records, compatibility, and rollback

No database, API, runtime behavior, migration, or stored fiscal record changes. Rollback is a documentation-only revert; protected evidence remains preserved independently.

Checks

  • corepack pnpm check: 147 passed, 0 failed/skipped/todo
  • production layout, license controls and 239-file secret scan: passed
  • production dependency audit: no known vulnerabilities
  • official TLS 1.3 Echo: passed
  • missing/unrelated client certificates: rejected as required
  • signed FURS S005: signature, chain, signer pin, schema and MessageID passed

Signed-off-by: Dejan Kletečki <120020919+Starfiniti@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant