A proposed local-first, agent-first Rust library and CLI for inspecting, listing, structurally validating, extracting, creating, signing, and verifying ETSI Associated Signature Containers (ASiC).
Status: scaffold. Only help, version, and capabilities [--json] are
implemented. No container parsing, extraction, creation, signing, timestamping,
or signature verification exists yet. There is no published release.
ASiC is the umbrella standard; ASiC-S and ASiC-E are container variants. The first planned implementation targets ASiC-E with XAdES. ASiC-S and CAdES support are separate roadmap items, not implied capabilities. This project is independent and is not endorsed by ETSI or the European Commission.
Build from this checkout with Rust 1.88 or newer:
cargo run --locked -p openasic-cli -- --help
cargo run --locked -p openasic-cli -- --version
cargo run --locked -p openasic-cli -- capabilities --jsonThe capabilities command reports the current implementation:
{
"schema_version": 1,
"ok": true,
"command": "capabilities",
"data": {
"project": "openASiC",
"stage": "scaffold",
"operations": []
},
"verified": false
}An empty operation list means no document operations are available.
verified: false means no cryptographic verification was performed.
- Bounded ASiC container inspection and safe extraction.
- Explicit structural validation, separate from cryptographic verification.
- Container creation and signing with precise document coverage.
- Verification against caller-supplied trust and revocation evidence.
- Human-readable output and stable, documented JSON contracts.
The planned tool owns ASiC packaging, manifests, and signature-scope rules. openSzigno owns ES3 dossiers, openKRX owns KRX packages, and openPapir owns correspondence workflows. None is a build dependency. Reusable signature machinery may later be extracted behind reviewed interfaces; no sibling parser or crypto stack is copied here.
A container format alone establishes no qualified signature or legal effect. Creating or signing a container must never claim that it was verified.
The workspace contains openasic-core and openasic-cli. Both crates are
unpublished, use Rust edition 2024, and are licensed under MIT.
The repository name is openASiC; the executable is lowercase openasic.
./scripts/check.sh
cargo build --release --lockedPull requests target develop; master is reserved for stable releases.
See contributing, security, and the
documentation index. The roadmap separates
profile discovery, implementation, and independent interoperability testing.
For an explicitly requested Claude orchestration session, prepare the ignored launch file from this checkout:
python3 scripts/prepare-orchestrator.pyThen ask Claude to read ./tmp/orchestrator.md and begin orchestrating.
Read runner setup for private host registration and tools,
and orchestrator instructions for claims, worker
ownership, independent review, and merge gates. A fresh clone does not include
private routing or credentials. Automatic dispatch remains disabled.