Civarro public keys
Public verification keys, published by Civarro. Private signing material stays in AWS Key Management Service.
Current JWKS · Key catalog · Consumer instructions and source
Chronovault reader approval
Verifies Civarro approval of an attested reader boot key for a specific vault, record and processing region. The vault must also verify fresh request possession, native SNP evidence and patient policy.
- Status
- active
- Algorithm
- ES256 (ECDSA P-256 with SHA-256)
- Key ID
spki-sha256-0b9412c748e0697e77f681ef44c213148020b99430da08a0b1a5dad18e3b9fa2
- SHA-256 fingerprint · DER SubjectPublicKeyInfo
0b9412c748e0697e77f681ef44c213148020b99430da08a0b1a5dad18e3b9fa2
Download public PEM · Verification example
OCI image release approval
Civarro release approval and redistribution. Does not authenticate the upstream author or authorize a Chronovault reader.
- Status
- active
- Algorithm
- ES256 (ECDSA P-256 with SHA-256)
- Key ID
spki-sha256-fb1483ec47e11cd271062266db7c79a7519632ac956759eb3d792e9d73f2c0aa
- SHA-256 fingerprint · DER SubjectPublicKeyInfo
fb1483ec47e11cd271062266db7c79a7519632ac956759eb3d792e9d73f2c0aa
Download public PEM · Verification example
Using these keys
Configure this trusted origin and the expected key purpose and ID independently of the signature being checked. Match the SHA-256 fingerprint, then verify the signature using the stated algorithm and the protocol's signed bytes.
Publication distributes keys; accepting a reader additionally requires the Chronovault approval protocol and patient policy checks. Image release signatures express Civarro release approval, not upstream authorship. Image and reader approval keys have separate purposes.
Updates and retirement
The release key has no scheduled expiration. Civarro plans to retain it for at least one year, subject to compromise or deliberate rotation. Unchanged releases do not need to be signed again for each demo.
The current JWKS contains active keys only. Retired or revoked keys may remain downloadable for historical inspection. Download availability does not authorize new signatures.
Refresh the catalog and JWKS at least every five minutes, and once on an unknown key ID. Reject unknown, retired or revoked keys for new acceptance. Fail closed after that refresh interval if fresh trust information cannot be obtained. Key removal takes effect when a consumer refreshes; it is not instantaneous revocation.