C2PA trust-list attribution Creator: C2PA - Coalition for Content Provenance and Authenticity Repository: https://github.com/c2pa-org/conformance-public Snapshot commit: 99927caef670ca4ad9da5e5542dca39e42fad6f3 Snapshot commit date: 2026-08-14T21:00:15Z Reviewed as of: 2026-09-18 Sources: https://github.com/c2pa-org/conformance-public/blob/99927caef670ca4ad9da5e5542dca39e42fad6f3/trust-list/C2PA-TRUST-LIST.pem https://github.com/c2pa-org/conformance-public/blob/99927caef670ca4ad9da5e5542dca39e42fad6f3/trust-list/C2PA-TSA-TRUST-LIST.pem License: Creative Commons Attribution 4.0 International (CC BY 4.0) https://creativecommons.org/licenses/by/4.0/ The complete upstream license, including its disclaimer of warranties, is distributed alongside this notice in c2pa-trust-license.txt. Upstream license: https://github.com/c2pa-org/conformance-public/blob/99927caef670ca4ad9da5e5542dca39e42fad6f3/LICENSE Modification: c2pa-trust.txt concatenates the official claim-signing PEM list, a single newline, and the official timestamping PEM list. Both original lists retain their exact bytes. No certificates were added or removed; certificates appearing in both source lists remain duplicated. No private, development, SDK test, or browser TLS roots were added. This project is not endorsed by C2PA. Byte hashes establish the identity of this fixed snapshot, not a current revocation check, independent verification of the list's signature, or verification of any user's media. Trust-list changes require explicit review and a newly pinned snapshot.