Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

[EPIC] Add eIDAS trust service interoperability

Aperta
#8,944 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

I maintainer di solito rispondono entro 1 giorno

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
5/5
Tempo stimato
Più di una settimana
Idoneità per principianti
20/100
Tipo di issue
Funzionalità
Chiarezza
Da chiarire
Stato di attività
Attiva

Direzione di ricerca

Do not implement this epic directly. Start by reviewing dependencies #8335, #8942, #8943, and #8946, then define the supported eIDAS signature levels, provider integrations, validation requirements, and interoperability tests. Done means those requirements are explicit and focused child issues can guide implementation with external trust services.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

This is a roadmap and funding epic.

[!IMPORTANT]

Do not implement this epic directly.

This issue exists to study, define and fund the work required for LibreSign to interoperate with European eIDAS trust services.

It must be implemented later through focused child issues. Discussion, requirements and references from trust service providers and European users are welcome.

Background

LibreSign is building the foundation for external and remote signing.

Supporting a remote certificate is not by itself the same as supporting the requirements and trust model used in the European eIDAS ecosystem.

LibreSign should integrate with qualified trust service providers instead of trying to become a trust service provider itself.

Goal

Make LibreSign able to use and validate signing services from the European eIDAS trust ecosystem through open and interoperable mechanisms.

The exact supported eIDAS signature levels and validation requirements must be defined during this epic before implementation starts.

Expected areas of work

This epic may include:

  • interoperability with Qualified Trust Service Providers (QTSPs);
  • remote signing through standards-based provider integrations such as CSC;
  • use of qualified certificates where applicable;
  • support for remote QSCD-based signing flows where provided by the trust service;
  • PAdES requirements needed by the selected eIDAS use cases;
  • certificate chain and revocation validation;
  • trusted service status and European Trusted List integration where required;
  • timestamp and long-term validation requirements where required;
  • interoperability testing with European services.

Important boundary

LibreSign should orchestrate the document signing process and integrate with trust services.

It should not claim to issue qualified certificates, operate a QSCD or become a QTSP unless that is ever addressed as a completely separate project.

Why this matters

Organizations using Nextcloud and LibreSign should be able to keep their document workflows under their own control while using trusted European signing services when a higher assurance level is required.

This creates a practical open-source bridge between self-hosted collaboration and the European digital trust ecosystem.

Business and funding value

This is directly relevant to European public administrations, companies and other organizations that need open digital signing workflows but rely on qualified external trust services for certificate and key operations.

It is also a strong candidate for public-interest and European digital sovereignty funding because the result remains reusable free software and is not tied to one QTSP.

Potential funders and validation partners include:

  • European organizations that already use LibreSign or Nextcloud;
  • QTSPs interested in open-source integrations;
  • public administrations and SMEs that need self-hosted signing workflows;
  • digital sovereignty and open infrastructure funds.

Dependencies

This epic depends on:

  • #8335;
  • #8942 for the remote signing provider architecture;
  • #8943 for CSC support where CSC is selected for a target trust service;
  • #8946 for the required PAdES and validation capabilities.

Out of scope

This epic does not promise generic “eIDAS compliance” without defining the supported signature level and validation scope.

Each supported level must have explicit technical requirements, tests and validation criteria.

Done when

LibreSign can complete and validate the agreed eIDAS-oriented signing workflows with independent European trust services, with the private key remaining under the control of the external qualified service when required.

Lingua principale
PHP
Stelle
828
Fork
157
Merge medio
6h 48m
PR unite (30g)
622

Preparare l'ambiente

Apri in Codespaces

Avvia il container di sviluppo del progetto nel browser, con il tuo account GitHub.

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di LibreSign/libresign

Tutte le issue di LibreSign/libresign

Issue simili

Altre issue su PHP

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.