Skip to content

examples/minimal README: placeholder root key, and "advisory" contradicts the config #218

Description

@imran-siddique

Checked at 8113abd.

Two things in examples/minimal/README.md:

  • Line 14 tells readers to run --trusted-root-issuer <trusted-root-issuer-hex>, but the real key is already pinned in ca2a-config.yaml (eda38c44...eb162). With that key, ca2a verify-chain --chain chain.json --trusted-root-issuer <key> returns {"verified": true, "hops": 3, "leaf_scope": ["cap:read"], ...}.
  • Line 7 calls the config "software-only, advisory". The file sets enforcement_mode: enforcing, and ca2a validate-config prints ok: provider=software-only enforcement=enforcing.

There is also no test for examples/minimal, while the other examples each have one.

Done when

  • the README uses the real key and says "enforcing"
  • a new tests/unit/test_example_minimal.py runs both commands through ca2a_runtime.cli.main and asserts verified: true and the config ok line

Files: examples/minimal/README.md, one new test file.

Activity

  1. aipd506 commented on Sep 30, 2026

    @aipd506
    Contributor

    Hi @agentrust-io maintainers! 👋

    I would like to resolve this issue and be vouched per CONTRIBUTING.md.

    Summary of the fix I have prepared:

    1. examples/minimal/README.md:
      • Replaced <trusted-root-issuer-hex> placeholder with the actual pinned key (eda38c446da3db3eba68852ca9869260c36badd48b2cab16ec8d8faf607eb162) defined in ca2a-config.yaml.
      • Corrected description of ca2a-config.yaml from (software-only, advisory) to (software-only, enforcing) to match the config.
    2. Unit Test Suite (tests/unit/test_example_minimal.py):
      • Runs ca2a verify-chain offline against examples/minimal/chain.json with the pinned key and asserts verified: True, hops: 3, and leaf_scope: ["cap:read"].
      • Runs ca2a validate-config against examples/minimal/ca2a-config.yaml and asserts exit code 0 and ok: provider=software-only enforcement=enforcing.

    Could you please add me with /vouch so my pull request can proceed with review? Thank you!

  2. imran-siddique commented on Sep 30, 2026

    @imran-siddique
    MemberAuthor

    /vouch @aipd506

  3. github-actions commented on Sep 30, 2026

    @github-actions
    Contributor

    @aipd506 is vouched by @imran-siddique. Pull requests from that account will not be closed by the vouch check.

  4. added a commit that references this issue on Sep 30, 2026
  5. aipd506 commented on Oct 1, 2026

    @aipd506
    Contributor

    Thank you @imran-siddique for the vouch. Pull request #220 is open and ready for your review whenever convenient.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions