C2PA Trust List
Definition
A curated list of trusted root certificate authorities whose chains can anchor a C2PA claim signature. Maintained by the C2PA organisation. A signature whose certificate does not chain to this list produces a valid cryptographic signature but an untrusted manifest, which is a distinct failure mode from a tampered manifest.
- Maintained by
- The C2PA organisation
- Contains
- Trusted root certificate authorities
- Failure mode 1
- Tampered manifest: signature invalid
- Failure mode 2
- Untrusted manifest: signature valid, chain not trusted
Common questions
Why does the distinction between an invalid signature and an untrusted certificate chain matter?+
An invalid signature means the manifest content was altered after signing, a strong tampering indicator. An untrusted chain means the manifest is internally consistent and correctly signed, but by a certificate authority the C2PA trust list does not recognise, which points to using a non-accredited tool rather than tampering.
Does a manifest failing the trust list check mean the media was faked?+
Not necessarily. It can mean the capture or editing software used a self-signed or non-participating certificate authority. Examiners treat an untrusted-chain result as inconclusive on authenticity and look for corroborating tampering evidence before drawing conclusions.
Related terms
- Assertion
- A single provenance statement inside a C2PA claim. Examples include the camera make and model, GPS coordinates at capture, an AI-training or...
- C2PA Manifest
- The structured provenance record embedded in or associated with a media file. Contains one or more signed claim blocks, each holding a...
- Claim Signature
- An X.509-based digital signature over the hashes of all assertions in a claim plus the content binding hash. Produced by the signer's...
- Hard Binding
- A content binding that stores SHA hashes of specific byte ranges of the media file inside the signed manifest. Any modification to...
- Soft Binding
- A content binding using a perceptual fingerprint or watermark embedded in the signal rather than the file bytes. Designed to survive format...