{
  "issuer": "European Digital Sovereignty Organization (EDSO)",
  "schema": "https://edso.eu/schema/trust-bundle/v1",
  "generatedAt": "2026-06-09T19:06:58.797Z",
  "productionAlgorithm": "Ed25519",
  "currentDemoAlgorithm": "HMAC-SHA256 (demo)",
  "keys": [
    {
      "kid": "edso-trust-2026-01",
      "algorithm": "HMAC-SHA256 (demo)",
      "status": "active",
      "validFrom": "2026-01-01T00:00:00Z",
      "validTo": "2028-01-01T00:00:00Z",
      "publicKey": "0ea329a4a2faf2d9bc36d5ae728ef1130f8188e1bd7a930d35116400089e4c7c",
      "comment": "Demo verifier identifier. Productive Ed25519 public keys will be published once the EDSO HSM is provisioned."
    }
  ],
  "rotation": {
    "intervalMonths": 24,
    "overlapMonths": 3
  },
  "notes": [
    "Trust bundle history is append-only; retired keys remain published to allow verification of older certificates.",
    "Production keys are managed by the EDSO Geschäftsstelle and rotated every 24 months with a 3-month overlap."
  ]
}