pask-wire-cli
Apache-2.0 command-line producer and supplied-key verifier for Pask statements.
The executable is pask-wire-cli. It supports implemented processing for
wilder.pser/0.5 and wilder.pser/0.6, not complete profile certification.
Current source evaluation
From a checkout of the reviewed source, with Rust stable (declared minimum 1.88):
Registry installation is prospective, only after an authorized publication:
Commands and formats
pask-wire-cli canonical-example
pask-wire-cli produce --input payload.json --private-key private.pem --output statement.cbor
pask-wire-cli verify --input statement.cbor --public-key public.pem --output payload.json
The private key is an Ed25519 PKCS#8 PEM (PRIVATE KEY). The public key is
Ed25519 SubjectPublicKeyInfo PEM (PUBLIC KEY), not an SSH public-key line.
verify writes canonical verified payload JSON to stdout or --output.
It does not output the full recipient coordinator report, automatically verify
attached SCITT Receipts, or establish a presented chain's contiguity.
canonical-example deliberately emits the legacy 0.5 example. The posted
-04/0.6 figure is generated by pask_wire::canonical_example_06() and guarded
by a separate workspace document test. No profile-selection option is provided.
Verification boundary
Success checks the statement signature under the caller-supplied Ed25519 key and the implemented payload checks. It does not authenticate the named organization or actor, establish physical truth, key hardware custody, or Transparency Service independence. The library's layered Receipt-validation APIs are separate from this CLI path. Legacy outer-subject typing and other known conformance limits remain disclosed in the repository's KNOWN-LIMITATIONS.
Crate semver, supported profile identifiers and draft revision are separate. The posted -04 draft is an Internet-Draft, not an IETF standard or endorsement.
License
Apache-2.0. The separate pask-adapt operational binary remains AGPL-3.0-only.