[MTCs] update some tests to draft-plants-04

There were some tests that only tested the draft-davidben-08 path.
Update them to plants-04. Since this CL is in preparation for removing
support for the old draft entirely, it just updates the tests in-place
rather than adding tests for both drafts.

Change-Id: I94688573b989d4cefb524ef05c585decc731f6bc
Bug: 520071497
Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/101127
Reviewed-by: David Benjamin <davidben@google.com>
Commit-Queue: Matt Mueller <mattm@google.com>
diff --git a/pki/testdata/verify_unittest/mtc-config.json b/pki/testdata/verify_unittest/mtc-config.json
index 2676874..c612a41 100644
--- a/pki/testdata/verify_unittest/mtc-config.json
+++ b/pki/testdata/verify_unittest/mtc-config.json
@@ -1,9 +1,17 @@
 {
-  "Version": "davidben-09",
-  "LogID": "32473.1",
+  "Version": "plants-04",
+  "ID": "32473.1",
+  "LogNumber": 1,
+  "Cosigners": [
+    {
+      "CosignerID": "32473.1",
+      "SignatureAlgorithm": "mldsa44",
+      "PrivateKey": "MDQCAQAwCwYJYIZIAWUDBAMRBCKAIAABAgMEBQYHCAkKCwwNDg8QERITFBUWFxgZGhscHR4f"
+    }
+  ],
   "Entries": [
     {
-      "Repeat": 8,
+      "Repeat": 9,
       "Subject": {
         "CommonName": "Filler certificates"
       },
diff --git a/pki/testdata/verify_unittest/mtc-leaf-b.pem b/pki/testdata/verify_unittest/mtc-leaf-b.pem
index d181b18..d4a24a0 100644
--- a/pki/testdata/verify_unittest/mtc-leaf-b.pem
+++ b/pki/testdata/verify_unittest/mtc-leaf-b.pem
@@ -1,11 +1,11 @@
 -----BEGIN CERTIFICATE-----
-MIIBjjCCAQWgAwIBAgIBCjAMBgorBgEEAYLaSy8AMBkxFzAVBgorBgEEAYLaSy8B
-DAczMjQ3My4xMB4XDTIwMDEwMTAwMDAwMFoXDTMwMTIzMTIzNTk1OVowADBZMBMG
-ByqGSM49AgEGCCqGSM49AwEHA0IABMsYgtepbbPkji/OzsB4Rg8yvf3clHe7DPNI
-wH+d1S/gFd/B6ByqZgOyyaGC3+MlYXFZXjXMbn7AH3D7nky19FajVTBTMA4GA1Ud
-DwEB/wQEAwIHgDAWBgNVHSUBAf8EDDAKBggrBgEFBQcDATApBgNVHREBAf8EHzAd
-ggliLmV4YW1wbGWCECouYmxhaC5iLmV4YW1wbGUwDAYKKwYBBAGC2ksvAAN1AAAA
-AAAAAAAIAAAAAAAAABAAYEU5Qbm6XiITuPIIBG/EvPYLIl1JMzJKZ3atLHkoGOAb
-x676xK7Ke7qP8w1tdF+k1wUIIjlmGT+aB2KOSOic0Wi/qlGnfqNJMluHRIvrrYnS
-pSqKdlven8bsZWqgWDrP9AAA
+MIIBkjCCAQugAwIBAgIHAQAAAAAACjAMBgorBgEEAYLaSy8AMBkxFzAVBgorBgEE
+AYLaSy8BDAczMjQ3My4xMB4XDTIwMDEwMTAwMDAwMFoXDTMwMTIzMTIzNTk1OVow
+ADBZMBMGByqGSM49AgEGCCqGSM49AwEHA0IABMsYgtepbbPkji/OzsB4Rg8yvf3c
+lHe7DPNIwH+d1S/gFd/B6ByqZgOyyaGC3+MlYXFZXjXMbn7AH3D7nky19FajVTBT
+MA4GA1UdDwEB/wQEAwIHgDAWBgNVHSUBAf8EDDAKBggrBgEFBQcDATApBgNVHREB
+Af8EHzAdggliLmV4YW1wbGWCECouYmxhaC5iLmV4YW1wbGUwDAYKKwYBBAGC2ksv
+AANzAAAAAAAAAAAIAAAAAAAQAGADaPHAKcaptKHsp2da08Jy9WW6UzQlKWYJzfoe
+RF0xIroyFtUgaA17H43oFPqWjefi50C8MzpB4A2KCRc7aTM83ScxvAWiKwAhfSqv
+1pSIs3Xz5Krj9hXQd89+xOW/D1YAAA==
 -----END CERTIFICATE-----
diff --git a/pki/testdata/verify_unittest/mtc-leaf-bitflip.pem b/pki/testdata/verify_unittest/mtc-leaf-bitflip.pem
index 70d152e..8c4a1b2 100644
--- a/pki/testdata/verify_unittest/mtc-leaf-bitflip.pem
+++ b/pki/testdata/verify_unittest/mtc-leaf-bitflip.pem
@@ -1,11 +1,11 @@
 -----BEGIN CERTIFICATE-----
-MIIBjjCCAQWgAwIBAgIBCTAMBgorBgEEAYLaSy8AMBkxFzAVBgorBgEEAYLaSy8B
-DAczMjQ3My4xMB4XDTIwMDEwMTAwMDAwMFoXDTMwMTIzMTIzNTk1OVowADBZMBMG
-ByqGSM49AgEGCCqGSM49AwEHA0IABMsYgtepbbPkji/OzsB4Rg8yvf3clHe7DPNI
-wH+d1S/gFd/B6ByqZgOyyaGC3+MlYXFZXjXMbn7AH3D7nky19FajVTBTMA4GA1Ud
-DwEB/wQEAwIHgDAWBgNVHSUBAf8EDDAKBggrBgEFBQcDATApBgNVHREBAf8EHzAd
-gglhLmV4YW1wbGWCECouYmxhaC5hLmV4YW1wbGUwDAYKKwYBBAGC2ksvAAN1AAAA
-AAAAAAAIAAAAAAAAAA0AYGbmiKnfNXzM/834NuaRq4i0xGTzYV6nx8s8iUliZgki
-gQcBu21ak6gq40RFYQpnPL0juf88bIJsdUymRTaKOe9FOUG5ul4iE7jyCARvxLz2
-CyJdSTMySmd2rSx5KBjgGwAA
+MIIBkjCCAQugAwIBAgIHAQAAAAAACTAMBgorBgEEAYLaSy8AMBkxFzAVBgorBgEE
+AYLaSy8BDAczMjQ3My4xMB4XDTIwMDEwMTAwMDAwMFoXDTMwMTIzMTIzNTk1OVow
+ADBZMBMGByqGSM49AgEGCCqGSM49AwEHA0IABMsYgtepbbPkji/OzsB4Rg8yvf3c
+lHe7DPNIwH+d1S/gFd/B6ByqZgOyyaGC3+MlYXFZXjXMbn7AH3D7nky19FajVTBT
+MA4GA1UdDwEB/wQEAwIHgDAWBgNVHSUBAf8EDDAKBggrBgEFBQcDATApBgNVHREB
+Af8EHzAdgglhLmV4YW1wbGWCECouYmxhaC5hLmV4YW1wbGUwDAYKKwYBBAGC2ksv
+AANzAAAAAAAAAAAIAAAAAAANAGAEgK6gczm8d8gKP5tFa2nRAk0ir2AEjDporD5o
+5huNWOraA53zncs3yWFVfBw1C95pfVJB5EMmJ/EMPEwtZLFTA2jxwCnGqbSh7Kdn
+WtPCcvVlulM0JSlmCc36HkRdMSIAAA==
 -----END CERTIFICATE-----
diff --git a/pki/testdata/verify_unittest/mtc-leaf-c.pem b/pki/testdata/verify_unittest/mtc-leaf-c.pem
index f40f175..eb0ab6c 100644
--- a/pki/testdata/verify_unittest/mtc-leaf-c.pem
+++ b/pki/testdata/verify_unittest/mtc-leaf-c.pem
@@ -1,10 +1,11 @@
 -----BEGIN CERTIFICATE-----
-MIIBezCB86ADAgECAgETMAwGCisGAQQBgtpLLwAwGTEXMBUGCisGAQQBgtpLLwEM
-BzMyNDczLjEwHhcNMjAwMTAxMDAwMDAwWhcNMzAxMjMxMjM1OTU5WjAAMFkwEwYH
-KoZIzj0CAQYIKoZIzj0DAQcDQgAEyxiC16lts+SOL87OwHhGDzK9/dyUd7sM80jA
-f53VL+AV38HoHKpmA7LJoYLf4yVhcVleNcxufsAfcPueTLX0VqNDMEEwDgYDVR0P
-AQH/BAQDAgeAMBYGA1UdJQEB/wQMMAoGCCsGAQUFBwMBMBcGA1UdEQEB/wQNMAuC
-CWMuZXhhbXBsZTAMBgorBgEEAYLaSy8AA3UAAAAAAAAAABAAAAAAAAAAGABgRTlB
-ubpeIhO48ggEb8S89gsiXUkzMkpndq0seSgY4BvkaISclDjMOiHjWnQVjQwcga3E
-eAlic9H5ARHDCvYTFkg9lSfzzvEVi2O7/esSu2PyEF9BBZ0x5YD/8oihdjQoAAA=
+MIIBfzCB+aADAgECAgcBAAAAAAATMAwGCisGAQQBgtpLLwAwGTEXMBUGCisGAQQB
+gtpLLwEMBzMyNDczLjEwHhcNMjAwMTAxMDAwMDAwWhcNMzAxMjMxMjM1OTU5WjAA
+MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEyxiC16lts+SOL87OwHhGDzK9/dyU
+d7sM80jAf53VL+AV38HoHKpmA7LJoYLf4yVhcVleNcxufsAfcPueTLX0VqNDMEEw
+DgYDVR0PAQH/BAQDAgeAMBYGA1UdJQEB/wQMMAoGCCsGAQUFBwMBMBcGA1UdEQEB
+/wQNMAuCCWMuZXhhbXBsZTAMBgorBgEEAYLaSy8AA3MAAAAAAAAAABAAAAAAABgA
+YANo8cApxqm0oeynZ1rTwnL1ZbpTNCUpZgnN+h5EXTEi3n7BWV1YiEcwgdTB75Vw
+9NF6ulTPsnQ68LkiqN63NEY2B38j4kagiB9RFst03akiQJqUQgnVr7Zz6gG5Cq8J
+tgAA
 -----END CERTIFICATE-----
diff --git a/pki/testdata/verify_unittest/mtc-leaf-unused-bit.pem b/pki/testdata/verify_unittest/mtc-leaf-unused-bit.pem
index 91612bb..ea4a145 100644
--- a/pki/testdata/verify_unittest/mtc-leaf-unused-bit.pem
+++ b/pki/testdata/verify_unittest/mtc-leaf-unused-bit.pem
@@ -1,11 +1,11 @@
 -----BEGIN CERTIFICATE-----
-MIIBjjCCAQWgAwIBAgIBCTAMBgorBgEEAYLaSy8AMBkxFzAVBgorBgEEAYLaSy8B
-DAczMjQ3My4xMB4XDTIwMDEwMTAwMDAwMFoXDTMwMTIzMTIzNTk1OVowADBZMBMG
-ByqGSM49AgEGCCqGSM49AwEHA0IABMsYgtepbbPkji/OzsB4Rg8yvf3clHe7DPNI
-wH+d1S/gFd/B6ByqZgOyyaGC3+MlYXFZXjXMbn7AH3D7nky19FajVTBTMA4GA1Ud
-DwEB/wQEAwIHgDAWBgNVHSUBAf8EDDAKBggrBgEFBQcDATApBgNVHREBAf8EHzAd
-gglhLmV4YW1wbGWCECouYmxhaC5hLmV4YW1wbGUwDAYKKwYBBAGC2ksvAAN1AQAA
-AAAAAAAIAAAAAAAAAA0AYGfmiKnfNXzM/834NuaRq4i0xGTzYV6nx8s8iUliZgki
-gQcBu21ak6gq40RFYQpnPL0juf88bIJsdUymRTaKOe9FOUG5ul4iE7jyCARvxLz2
-CyJdSTMySmd2rSx5KBjgGwAA
+MIIBkjCCAQugAwIBAgIHAQAAAAAACTAMBgorBgEEAYLaSy8AMBkxFzAVBgorBgEE
+AYLaSy8BDAczMjQ3My4xMB4XDTIwMDEwMTAwMDAwMFoXDTMwMTIzMTIzNTk1OVow
+ADBZMBMGByqGSM49AgEGCCqGSM49AwEHA0IABMsYgtepbbPkji/OzsB4Rg8yvf3c
+lHe7DPNIwH+d1S/gFd/B6ByqZgOyyaGC3+MlYXFZXjXMbn7AH3D7nky19FajVTBT
+MA4GA1UdDwEB/wQEAwIHgDAWBgNVHSUBAf8EDDAKBggrBgEFBQcDATApBgNVHREB
+Af8EHzAdgglhLmV4YW1wbGWCECouYmxhaC5hLmV4YW1wbGUwDAYKKwYBBAGC2ksv
+AANzAQAAAAAAAAAIAAAAAAANAGAFgK6gczm8d8gKP5tFa2nRAk0ir2AEjDporD5o
+5huNWOraA53zncs3yWFVfBw1C95pfVJB5EMmJ/EMPEwtZLFTA2jxwCnGqbSh7Kdn
+WtPCcvVlulM0JSlmCc36HkRdMSIAAA==
 -----END CERTIFICATE-----
diff --git a/pki/testdata/verify_unittest/mtc-leaf.pem b/pki/testdata/verify_unittest/mtc-leaf.pem
index d9ce153..790b812 100644
--- a/pki/testdata/verify_unittest/mtc-leaf.pem
+++ b/pki/testdata/verify_unittest/mtc-leaf.pem
@@ -1,11 +1,11 @@
 -----BEGIN CERTIFICATE-----
-MIIBjjCCAQWgAwIBAgIBCTAMBgorBgEEAYLaSy8AMBkxFzAVBgorBgEEAYLaSy8B
-DAczMjQ3My4xMB4XDTIwMDEwMTAwMDAwMFoXDTMwMTIzMTIzNTk1OVowADBZMBMG
-ByqGSM49AgEGCCqGSM49AwEHA0IABMsYgtepbbPkji/OzsB4Rg8yvf3clHe7DPNI
-wH+d1S/gFd/B6ByqZgOyyaGC3+MlYXFZXjXMbn7AH3D7nky19FajVTBTMA4GA1Ud
-DwEB/wQEAwIHgDAWBgNVHSUBAf8EDDAKBggrBgEFBQcDATApBgNVHREBAf8EHzAd
-gglhLmV4YW1wbGWCECouYmxhaC5hLmV4YW1wbGUwDAYKKwYBBAGC2ksvAAN1AAAA
-AAAAAAAIAAAAAAAAAA0AYGfmiKnfNXzM/834NuaRq4i0xGTzYV6nx8s8iUliZgki
-gQcBu21ak6gq40RFYQpnPL0juf88bIJsdUymRTaKOe9FOUG5ul4iE7jyCARvxLz2
-CyJdSTMySmd2rSx5KBjgGwAA
+MIIBkjCCAQugAwIBAgIHAQAAAAAACTAMBgorBgEEAYLaSy8AMBkxFzAVBgorBgEE
+AYLaSy8BDAczMjQ3My4xMB4XDTIwMDEwMTAwMDAwMFoXDTMwMTIzMTIzNTk1OVow
+ADBZMBMGByqGSM49AgEGCCqGSM49AwEHA0IABMsYgtepbbPkji/OzsB4Rg8yvf3c
+lHe7DPNIwH+d1S/gFd/B6ByqZgOyyaGC3+MlYXFZXjXMbn7AH3D7nky19FajVTBT
+MA4GA1UdDwEB/wQEAwIHgDAWBgNVHSUBAf8EDDAKBggrBgEFBQcDATApBgNVHREB
+Af8EHzAdgglhLmV4YW1wbGWCECouYmxhaC5hLmV4YW1wbGUwDAYKKwYBBAGC2ksv
+AANzAAAAAAAAAAAIAAAAAAANAGAFgK6gczm8d8gKP5tFa2nRAk0ir2AEjDporD5o
+5huNWOraA53zncs3yWFVfBw1C95pfVJB5EMmJ/EMPEwtZLFTA2jxwCnGqbSh7Kdn
+WtPCcvVlulM0JSlmCc36HkRdMSIAAA==
 -----END CERTIFICATE-----
diff --git a/pki/testdata/verify_unittest/readme-mtc-certs.md b/pki/testdata/verify_unittest/readme-mtc-certs.md
index a8ebb6e..1113176 100644
--- a/pki/testdata/verify_unittest/readme-mtc-certs.md
+++ b/pki/testdata/verify_unittest/readme-mtc-certs.md
@@ -13,7 +13,7 @@
 ## Instructions
 
 - Run
-  `go run github.com/ietf-plants-wg/merkle-tree-certs/demo@b0c83104918f10e8c813783f77434143eab4ef97 -config=mtc-config.json`
+  `go run github.com/ietf-plants-wg/merkle-tree-certs/demo@9029a99bcfa4e91b8b8e9ba646ac386a6e1c208f -config=mtc-config.json -out=out`
 - copy/move the following output files:
   - `out/cert_9_0.pem` to `mtc-leaf.pem`
   - `out/cert_9_1.pem` to `mtc-leaf-bitflip.pem`
@@ -23,4 +23,4 @@
 - edit `VerifyMTCTest::SetUp` to set the trusted subtrees to the ones output by
   the above command.
 - remove other artifacts created by the merkle-tree-certs/demo tool (e.g.
-  `rm -r out`).
\ No newline at end of file
+  `rm -r out`).
diff --git a/pki/trust_store_collection_unittest.cc b/pki/trust_store_collection_unittest.cc
index 8c82349..3902ba9 100644
--- a/pki/trust_store_collection_unittest.cc
+++ b/pki/trust_store_collection_unittest.cc
@@ -214,21 +214,21 @@
     // Create modified versions of `mtc_leaf_` with different issuers. These
     // don't need to be able to verify, we just need certs with different
     // issuers to test the issuer lookup in GetTrustedMTCIssuerOf.
-    constexpr char kLogId2Str[] = "32473.2";
-    mtc_leaf2_ = ModifyLeafWithIssuerLogId(kLogId2Str);
+    constexpr char kCaId2Str[] = "32473.2";
+    mtc_leaf2_ = ModifyLeafWithIssuerCaId(kCaId2Str);
     ASSERT_TRUE(mtc_leaf2_);
 
-    constexpr char kLogId3Str[] = "32473.3";
-    mtc_leaf3_ = ModifyLeafWithIssuerLogId(kLogId3Str);
+    constexpr char kCaId3Str[] = "32473.3";
+    mtc_leaf3_ = ModifyLeafWithIssuerCaId(kCaId3Str);
     ASSERT_TRUE(mtc_leaf3_);
   }
 
-  std::shared_ptr<const ParsedCertificate> ModifyLeafWithIssuerLogId(
-      std::string_view new_log_id) {
-    // The log_id encoded in the issuer name of mtc-leaf.pem.
-    constexpr std::string_view log_id_str = "32473.1";
+  std::shared_ptr<const ParsedCertificate> ModifyLeafWithIssuerCaId(
+      std::string_view new_ca_id) {
+    // The ca_id encoded in the issuer name of mtc-leaf.pem.
+    constexpr std::string_view ca_id_str = "32473.1";
 
-    if (new_log_id.size() != log_id_str.size()) {
+    if (new_ca_id.size() != ca_id_str.size()) {
       ADD_FAILURE() << "invalid replacement string";
       return nullptr;
     }
@@ -236,15 +236,15 @@
     std::vector<uint8_t> leaf_der2(mtc_leaf_->der_cert().begin(),
                                    mtc_leaf_->der_cert().end());
 
-    // find the log_id_str in leaf_der2 and replace the bytes with
-    // new log id.
-    auto it = std::search(leaf_der2.begin(), leaf_der2.end(),
-                          log_id_str.begin(), log_id_str.end());
+    // find the ca_id_str in leaf_der2 and replace the bytes with
+    // new CA id.
+    auto it = std::search(leaf_der2.begin(), leaf_der2.end(), ca_id_str.begin(),
+                          ca_id_str.end());
     if (it == leaf_der2.end()) {
-      ADD_FAILURE() << "log id not found";
+      ADD_FAILURE() << "CA id not found";
       return nullptr;
     }
-    std::copy(new_log_id.begin(), new_log_id.end(), it);
+    std::copy(new_ca_id.begin(), new_ca_id.end(), it);
 
     CertErrors errors;
     std::shared_ptr<const ParsedCertificate> mtc_leaf2 =
@@ -268,17 +268,22 @@
 }
 
 TEST_F(TrustStoreCollectionMtcTest, MtcTwoStores) {
-  constexpr uint8_t kLogid1[] = {0x81, 0xfd, 0x59, 0x01};
-  constexpr uint8_t kLogid2[] = {0x81, 0xfd, 0x59, 0x02};
-  constexpr uint8_t kLogid3[] = {0x81, 0xfd, 0x59, 0x03};
+  constexpr uint8_t kCaId1[] = {0x81, 0xfd, 0x59, 0x01};
+  constexpr uint8_t kCaId2[] = {0x81, 0xfd, 0x59, 0x02};
+  constexpr uint8_t kCaId3[] = {0x81, 0xfd, 0x59, 0x03};
 
-  Span<const TrustedSubtree> trusted_subtrees;
-  std::shared_ptr<const MTCAnchor> mtc_anchor1 =
-      std::make_shared<MTCAnchor>(MakeSpan(kLogid1), trusted_subtrees);
-  std::shared_ptr<const MTCAnchor> mtc_anchor2 =
-      std::make_shared<MTCAnchor>(MakeSpan(kLogid2), trusted_subtrees);
-  std::shared_ptr<const MTCAnchor> mtc_anchor3 =
-      std::make_shared<MTCAnchor>(MakeSpan(kLogid3), trusted_subtrees);
+  std::map<uint16_t, std::vector<TrustedSubtree>> trusted_subtrees;
+  // The ca_key doesn't need to be valid for this test.
+  UniquePtr<CRYPTO_BUFFER> ca_spki(CRYPTO_BUFFER_new({}, 0, nullptr));
+  auto mtc_anchor1 = std::make_shared<MTCAnchor>(
+      MakeSpan(kCaId1), SignatureAlgorithm::kMldsa44, UpRef(ca_spki),
+      trusted_subtrees);
+  auto mtc_anchor2 = std::make_shared<MTCAnchor>(
+      MakeSpan(kCaId2), SignatureAlgorithm::kMldsa44, UpRef(ca_spki),
+      trusted_subtrees);
+  auto mtc_anchor3 = std::make_shared<MTCAnchor>(
+      MakeSpan(kCaId3), SignatureAlgorithm::kMldsa44, UpRef(ca_spki),
+      trusted_subtrees);
 
   TrustStoreCollection collection;
   TrustStoreInMemory in_memory1;
diff --git a/pki/trust_store_in_memory_unittest.cc b/pki/trust_store_in_memory_unittest.cc
index 962bb51..0aea227 100644
--- a/pki/trust_store_in_memory_unittest.cc
+++ b/pki/trust_store_in_memory_unittest.cc
@@ -131,14 +131,15 @@
   EXPECT_TRUE(in_memory.IsEmpty());
 
   // After adding an MTC root, it is no longer empty:
-  static const uint8_t kValidLogId[] = {42};  // relative OID of 42
-  TrustedSubtree a;
-  a.range = Subtree{0, 4};
-  std::vector<TrustedSubtree> valid_subtrees = {a};
-  std::shared_ptr<MTCAnchor> valid_anchor =
-      std::make_shared<MTCAnchor>(kValidLogId, MakeSpan(valid_subtrees));
-  EXPECT_TRUE(valid_anchor->IsValid());
-  EXPECT_TRUE(in_memory.AddMTCTrustAnchor(valid_anchor));
+  static const uint8_t kMtcCaId[] = {42};  // relative OID of 42
+  // The ca_key doesn't need to be valid for this test.
+  UniquePtr<CRYPTO_BUFFER> ca_spki(CRYPTO_BUFFER_new({}, 0, nullptr));
+  std::map<uint16_t, std::vector<TrustedSubtree>> trusted_subtrees;
+  auto mtc_anchor = std::make_shared<MTCAnchor>(
+      MakeSpan(kMtcCaId), SignatureAlgorithm::kMldsa44, UpRef(ca_spki),
+      trusted_subtrees);
+  EXPECT_TRUE(mtc_anchor->IsValid());
+  EXPECT_TRUE(in_memory.AddMTCTrustAnchor(mtc_anchor));
   EXPECT_FALSE(in_memory.IsEmpty());
 
   // It is empty again after a call to Clear:
@@ -150,45 +151,52 @@
   TrustStoreInMemory in_memory;
 
   // AddMTCTrustAnchor should fail if the MTCAnchor is invalid.
-  static const uint8_t kValidLogId[] = {42};  // relative OID of 42
+  static const uint8_t kValidCaId[] = {42};  // relative OID of 42
   TrustedSubtree a;
   a.range = Subtree{0, 4};
   TrustedSubtree b;
   b.range = Subtree{0, 6};
   TrustedSubtree c;
   c.range = Subtree{8, 9};
-  std::vector<TrustedSubtree> valid_subtrees = {a, b, c};
-  std::shared_ptr<MTCAnchor> valid_anchor =
-      std::make_shared<MTCAnchor>(kValidLogId, MakeSpan(valid_subtrees));
+  std::map<uint16_t, std::vector<TrustedSubtree>> valid_subtrees;
+  valid_subtrees[1] = {a, b, c};
+  // The ca_key doesn't need to be valid for this test.
+  UniquePtr<CRYPTO_BUFFER> ca_spki(CRYPTO_BUFFER_new({}, 0, nullptr));
+  std::shared_ptr<MTCAnchor> valid_anchor = std::make_shared<MTCAnchor>(
+      kValidCaId, SignatureAlgorithm::kMldsa44, UpRef(ca_spki), valid_subtrees);
   EXPECT_TRUE(valid_anchor->IsValid());
-  EXPECT_EQ(valid_anchor->log_id(), kValidLogId);
+  EXPECT_EQ(valid_anchor->ca_id(), kValidCaId);
   EXPECT_TRUE(in_memory.AddMTCTrustAnchor(valid_anchor));
 
   {
-    // Attempting to add another MTCTrustAnchor with the same Log ID should fail
+    // Attempting to add another MTCTrustAnchor with the same CA ID should fail
     TrustedSubtree d;
     d.range = Subtree{16, 17};
-    std::vector<TrustedSubtree> subtrees = {d};
-    std::shared_ptr<MTCAnchor> anchor =
-        std::make_shared<MTCAnchor>(kValidLogId, MakeSpan(subtrees));
+    std::map<uint16_t, std::vector<TrustedSubtree>> subtrees;
+    subtrees[1] = {d};
+    std::shared_ptr<MTCAnchor> anchor = std::make_shared<MTCAnchor>(
+        kValidCaId, SignatureAlgorithm::kMldsa44, UpRef(ca_spki), subtrees);
     EXPECT_TRUE(anchor->IsValid());
     EXPECT_FALSE(in_memory.AddMTCTrustAnchor(anchor));
   }
 
   {
-    static const uint8_t kInvalidLogId[] = {
+    static const uint8_t kInvalidCaId[] = {
         255};  // The high bit is set, indicating this relative OID has more
                // bytes, but there are no more bytes.
     std::shared_ptr<MTCAnchor> invalid_anchor =
-        std::make_shared<MTCAnchor>(kInvalidLogId, MakeSpan(valid_subtrees));
+        std::make_shared<MTCAnchor>(kInvalidCaId, SignatureAlgorithm::kMldsa44,
+                                    UpRef(ca_spki), valid_subtrees);
     EXPECT_FALSE(invalid_anchor->IsValid());
     EXPECT_FALSE(in_memory.AddMTCTrustAnchor(invalid_anchor));
   }
 
   {
-    std::vector<TrustedSubtree> invalid_subtrees = {b, a, c};
+    std::map<uint16_t, std::vector<TrustedSubtree>> invalid_subtrees;
+    invalid_subtrees[1] = {b, a, c};
     std::shared_ptr<MTCAnchor> invalid_anchor =
-        std::make_shared<MTCAnchor>(kValidLogId, MakeSpan(invalid_subtrees));
+        std::make_shared<MTCAnchor>(kValidCaId, SignatureAlgorithm::kMldsa44,
+                                    UpRef(ca_spki), invalid_subtrees);
     EXPECT_FALSE(invalid_anchor->IsValid());
     EXPECT_FALSE(in_memory.AddMTCTrustAnchor(invalid_anchor));
   }
@@ -196,9 +204,11 @@
   {
     TrustedSubtree subtree;
     subtree.range = Subtree{4, 9};
-    std::vector<TrustedSubtree> invalid_subtrees = {subtree};
+    std::map<uint16_t, std::vector<TrustedSubtree>> invalid_subtrees;
+    invalid_subtrees[1] = {subtree};
     std::shared_ptr<MTCAnchor> invalid_anchor =
-        std::make_shared<MTCAnchor>(kValidLogId, MakeSpan(invalid_subtrees));
+        std::make_shared<MTCAnchor>(kValidCaId, SignatureAlgorithm::kMldsa44,
+                                    UpRef(ca_spki), invalid_subtrees);
     EXPECT_FALSE(invalid_anchor->IsValid());
     EXPECT_FALSE(in_memory.AddMTCTrustAnchor(invalid_anchor));
   }
@@ -208,17 +218,20 @@
   TrustStoreInMemory in_memory1;
   TrustStoreInMemory in_memory2;
 
-  static const uint8_t kValidLogId1[] = {42};  // relative OID of 42
-  static const uint8_t kValidLogId2[] = {43};  // relative OID of 43
-  std::vector<TrustedSubtree> subtrees;
-  std::shared_ptr<MTCAnchor> anchor1 =
-      std::make_shared<MTCAnchor>(kValidLogId1, MakeSpan(subtrees));
-  std::shared_ptr<MTCAnchor> anchor1_dup =
-      std::make_shared<MTCAnchor>(kValidLogId1, MakeSpan(subtrees));
-  std::shared_ptr<MTCAnchor> anchor2 =
-      std::make_shared<MTCAnchor>(kValidLogId2, MakeSpan(subtrees));
-  std::shared_ptr<MTCAnchor> anchor2_dup =
-      std::make_shared<MTCAnchor>(kValidLogId2, MakeSpan(subtrees));
+  static const uint8_t kValidCaId1[] = {42};  // relative OID of 42
+  static const uint8_t kValidCaId2[] = {43};  // relative OID of 43
+  std::map<uint16_t, std::vector<TrustedSubtree>> subtrees;
+  // The ca_key doesn't need to be valid for this test.
+  UniquePtr<CRYPTO_BUFFER> ca_spki(CRYPTO_BUFFER_new({}, 0, nullptr));
+
+  std::shared_ptr<MTCAnchor> anchor1 = std::make_shared<MTCAnchor>(
+      kValidCaId1, SignatureAlgorithm::kMldsa44, UpRef(ca_spki), subtrees);
+  std::shared_ptr<MTCAnchor> anchor1_dup = std::make_shared<MTCAnchor>(
+      kValidCaId1, SignatureAlgorithm::kMldsa44, UpRef(ca_spki), subtrees);
+  std::shared_ptr<MTCAnchor> anchor2 = std::make_shared<MTCAnchor>(
+      kValidCaId2, SignatureAlgorithm::kMldsa44, UpRef(ca_spki), subtrees);
+  std::shared_ptr<MTCAnchor> anchor2_dup = std::make_shared<MTCAnchor>(
+      kValidCaId2, SignatureAlgorithm::kMldsa44, UpRef(ca_spki), subtrees);
 
   ASSERT_TRUE(in_memory1.AddMTCTrustAnchor(anchor1));
   ASSERT_TRUE(in_memory2.AddMTCTrustAnchor(anchor2));
diff --git a/pki/verify_unittest.cc b/pki/verify_unittest.cc
index 31205a3..b959c7d 100644
--- a/pki/verify_unittest.cc
+++ b/pki/verify_unittest.cc
@@ -21,6 +21,7 @@
 
 #include <gmock/gmock.h>
 #include <gtest/gtest.h>
+#include <openssl/bytestring.h>
 #include <openssl/pki/verify.h>
 #include <openssl/pki/verify_error.h>
 #include <openssl/pool.h>
@@ -179,11 +180,40 @@
   ASSERT_TRUE(CertificateVerify(opts, &error)) << error.DiagnosticString();
 }
 
+namespace {
+UniquePtr<CRYPTO_BUFFER> ExportPublicKeyFromSeed(Span<const uint8_t> seed) {
+  UniquePtr<EVP_PKEY> pkey(EVP_PKEY_from_private_seed(
+      EVP_pkey_ml_dsa_44(), seed.data(), seed.size()));
+  if (!pkey) {
+    return nullptr;
+  }
+
+  ScopedCBB cbb;
+  if (!CBB_init(cbb.get(), 0) ||
+      !EVP_marshal_public_key(cbb.get(), pkey.get())) {
+    return nullptr;
+  }
+  return UniquePtr<CRYPTO_BUFFER>(
+      CRYPTO_BUFFER_new(CBB_data(cbb.get()), CBB_len(cbb.get()), nullptr));
+}
+}  // namespace
+
+// TODO(crbug.com/452986180): These MTC tests only test the landmark relative
+// path, the standalone MTC tests all ended up in path_builder_unittest. Should
+// probably have at least one or two standalone tests that go through this
+// interface.
 class VerifyMTCTest : public ::testing::Test {
  public:
   VerifyMTCTest() = default;
 
   void SetUp() override {
+    static constexpr uint8_t kCaPrivateKeySeed[] = {
+        0x00, 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07, 0x08, 0x09, 0x0a,
+        0x0b, 0x0c, 0x0d, 0x0e, 0x0f, 0x10, 0x11, 0x12, 0x13, 0x14, 0x15,
+        0x16, 0x17, 0x18, 0x19, 0x1a, 0x1b, 0x1c, 0x1d, 0x1e, 0x1f};
+    ca_spki_ = ExportPublicKeyFromSeed(kCaPrivateKeySeed);
+    ASSERT_TRUE(ca_spki_);
+
     ASSERT_TRUE(ReadTestCertPem("mtc-leaf.pem", &generic_cert_));
     ASSERT_TRUE(ReadTestCertPem("mtc-leaf-bitflip.pem", &bitflip_cert_));
     ASSERT_TRUE(ReadTestCertPem("mtc-leaf-unused-bit.pem", &unused_bit_cert_));
@@ -191,13 +221,13 @@
     ASSERT_TRUE(ReadTestCertPem("mtc-leaf-c.pem", &leaf_c_));
 
     ASSERT_TRUE(
-        CreateTrustedSubtree("Rrynt7BBSfI4WMZ1u1+XOJSNaWnYOdUDjn7VbdF+kQY=", 8,
+        CreateTrustedSubtree("+g71+77yhXVIT2NWwsHWnTz8TFyJ6yT9TLDGOW+Vi6k=", 8,
                              13, &generic_cert_subtree_));
     ASSERT_TRUE(
-        CreateTrustedSubtree("S92aoQXoNnSPJ37X1zY5InskJPTpzUs6LRr3TOwInvo=", 8,
+        CreateTrustedSubtree("sj2WUzCsih+fREf46unoF/8kyGr6tEpL/hlzn9D9994=", 8,
                              16, &leaf_b_subtree_));
     ASSERT_TRUE(
-        CreateTrustedSubtree("FxyVwc4letskl3WVKXWqlPBvUZsl5NiD5sW7Wr50k+4=", 16,
+        CreateTrustedSubtree("bGiRKKU8PI5RTxSYgzL2nGvnUE4d/l09y6JaLCbqgy8=", 16,
                              24, &leaf_c_subtree_));
   }
 
@@ -248,6 +278,8 @@
   }
 
  protected:
+  UniquePtr<CRYPTO_BUFFER> ca_spki_;
+
   std::string generic_cert_;
   std::string bitflip_cert_;
   std::string unused_bit_cert_;
@@ -262,19 +294,22 @@
   // Subtree for `leaf_c_` which does not overlap with any other subtrees.
   TrustedSubtree leaf_c_subtree_;
 
-  // Relative OID encoding of 32473.1, the log ID used for the MTC Anchor that
+  // Relative OID encoding of 32473.1, the CA ID used for the MTC Anchor that
   // issued the test MTCs in this test fixture.
-  static constexpr uint8_t kAnchorLogId[] = {0x81, 0xfd, 0x59, 0x01};
-  static constexpr uint8_t kAnchorLogIdBitflip[] = {0x81, 0xfd, 0x59, 0x00};
+  static constexpr uint8_t kCaId[] = {0x81, 0xfd, 0x59, 0x01};
+  static constexpr uint8_t kCaBitflipId[] = {0x81, 0xfd, 0x59, 0x00};
+  // The test certs for this test all use log number 1.
+  static constexpr uint16_t kLogNumber = 1;
 };
 
 TEST_F(VerifyMTCTest, SignaturelessMTC) {
   // Configure the trust store to trust the MTC anchor with the landmark subtree
   // for `generic_cert_`.
   std::unique_ptr<VerifyTrustStore> trust_store = EmptyTrustStore();
-  std::vector<TrustedSubtree> trusted_subtrees = {generic_cert_subtree_};
-  auto mtc_anchor = std::make_shared<MTCAnchor>(MakeSpan(kAnchorLogId),
-                                                MakeSpan(trusted_subtrees));
+  std::map<uint16_t, std::vector<TrustedSubtree>> subtrees;
+  subtrees[kLogNumber] = {generic_cert_subtree_};
+  auto mtc_anchor = std::make_shared<MTCAnchor>(
+      MakeSpan(kCaId), SignatureAlgorithm::kMldsa44, UpRef(ca_spki_), subtrees);
   ASSERT_TRUE(trust_store->trust_store->AddMTCTrustAnchor(mtc_anchor));
 
   CertificateVerifyOptions opts;
@@ -301,9 +336,10 @@
   std::unique_ptr<VerifyTrustStore> trust_store = EmptyTrustStore();
   trust_store->trust_store->AddCertificate(CertFromString(generic_cert_),
                                            CertificateTrust::ForDistrusted());
-  std::vector<TrustedSubtree> trusted_subtrees = {generic_cert_subtree_};
-  auto mtc_anchor = std::make_shared<MTCAnchor>(MakeSpan(kAnchorLogId),
-                                                MakeSpan(trusted_subtrees));
+  std::map<uint16_t, std::vector<TrustedSubtree>> subtrees;
+  subtrees[kLogNumber] = {generic_cert_subtree_};
+  auto mtc_anchor = std::make_shared<MTCAnchor>(
+      MakeSpan(kCaId), SignatureAlgorithm::kMldsa44, UpRef(ca_spki_), subtrees);
   ASSERT_TRUE(trust_store->trust_store->AddMTCTrustAnchor(mtc_anchor));
 
   CertificateVerifyOptions opts;
@@ -315,9 +351,10 @@
 
 TEST_F(VerifyMTCTest, WrongProof) {
   std::unique_ptr<VerifyTrustStore> trust_store = EmptyTrustStore();
-  std::vector<TrustedSubtree> trusted_subtrees = {generic_cert_subtree_};
-  auto mtc_anchor = std::make_shared<MTCAnchor>(MakeSpan(kAnchorLogId),
-                                                MakeSpan(trusted_subtrees));
+  std::map<uint16_t, std::vector<TrustedSubtree>> subtrees;
+  subtrees[kLogNumber] = {generic_cert_subtree_};
+  auto mtc_anchor = std::make_shared<MTCAnchor>(
+      MakeSpan(kCaId), SignatureAlgorithm::kMldsa44, UpRef(ca_spki_), subtrees);
   ASSERT_TRUE(trust_store->trust_store->AddMTCTrustAnchor(mtc_anchor));
 
   CertificateVerifyOptions opts;
@@ -330,9 +367,10 @@
 
 TEST_F(VerifyMTCTest, UnusedBit) {
   std::unique_ptr<VerifyTrustStore> trust_store = EmptyTrustStore();
-  std::vector<TrustedSubtree> trusted_subtrees = {generic_cert_subtree_};
-  auto mtc_anchor = std::make_shared<MTCAnchor>(MakeSpan(kAnchorLogId),
-                                                MakeSpan(trusted_subtrees));
+  std::map<uint16_t, std::vector<TrustedSubtree>> subtrees;
+  subtrees[kLogNumber] = {generic_cert_subtree_};
+  auto mtc_anchor = std::make_shared<MTCAnchor>(
+      MakeSpan(kCaId), SignatureAlgorithm::kMldsa44, UpRef(ca_spki_), subtrees);
   ASSERT_TRUE(trust_store->trust_store->AddMTCTrustAnchor(mtc_anchor));
 
   CertificateVerifyOptions opts;
@@ -343,14 +381,16 @@
             VerifyError::StatusCode::CERTIFICATE_INVALID_SIGNATURE);
 }
 
-TEST_F(VerifyMTCTest, WrongLogID) {
-  // Trust the correct subtree for `generic_cert_` but with the wrong log ID.
+TEST_F(VerifyMTCTest, WrongCaId) {
+  // Trust the correct subtree for `generic_cert_` but with the wrong CA ID.
   // Verifying the cert should fail because even though the proof evaluates to a
   // valid hash, the hash is for the wrong issuer.
   std::unique_ptr<VerifyTrustStore> trust_store = EmptyTrustStore();
-  std::vector<TrustedSubtree> trusted_subtrees = {generic_cert_subtree_};
-  auto mtc_anchor = std::make_shared<MTCAnchor>(MakeSpan(kAnchorLogIdBitflip),
-                                                MakeSpan(trusted_subtrees));
+  std::map<uint16_t, std::vector<TrustedSubtree>> subtrees;
+  subtrees[kLogNumber] = {generic_cert_subtree_};
+  auto mtc_anchor = std::make_shared<MTCAnchor>(MakeSpan(kCaBitflipId),
+                                                SignatureAlgorithm::kMldsa44,
+                                                UpRef(ca_spki_), subtrees);
   ASSERT_TRUE(trust_store->trust_store->AddMTCTrustAnchor(mtc_anchor));
 
   CertificateVerifyOptions opts;
@@ -364,9 +404,10 @@
   // Configure the trust store to trust the MTC anchor with the landmark subtree
   // for `generic_cert_`.
   std::unique_ptr<VerifyTrustStore> trust_store = EmptyTrustStore();
-  std::vector<TrustedSubtree> trusted_subtrees = {generic_cert_subtree_};
-  auto mtc_anchor = std::make_shared<MTCAnchor>(MakeSpan(kAnchorLogId),
-                                                MakeSpan(trusted_subtrees));
+  std::map<uint16_t, std::vector<TrustedSubtree>> subtrees;
+  subtrees[kLogNumber] = {generic_cert_subtree_};
+  auto mtc_anchor = std::make_shared<MTCAnchor>(
+      MakeSpan(kCaId), SignatureAlgorithm::kMldsa44, UpRef(ca_spki_), subtrees);
   ASSERT_TRUE(trust_store->trust_store->AddMTCTrustAnchor(mtc_anchor));
 
   CertificateVerifyOptions opts;
@@ -402,10 +443,11 @@
   // wrong hash. Configure the trust store to trust the MTC anchor with the
   // landmark subtree for `generic_cert_`.
   std::unique_ptr<VerifyTrustStore> trust_store = EmptyTrustStore();
-  std::vector<TrustedSubtree> trusted_subtrees = {generic_cert_subtree_};
-  trusted_subtrees[0].hash[0] ^= 1;
-  auto mtc_anchor = std::make_shared<MTCAnchor>(MakeSpan(kAnchorLogId),
-                                                MakeSpan(trusted_subtrees));
+  std::map<uint16_t, std::vector<TrustedSubtree>> subtrees;
+  subtrees[kLogNumber] = {generic_cert_subtree_};
+  subtrees[kLogNumber][0].hash[0] ^= 1;
+  auto mtc_anchor = std::make_shared<MTCAnchor>(
+      MakeSpan(kCaId), SignatureAlgorithm::kMldsa44, UpRef(ca_spki_), subtrees);
   ASSERT_TRUE(trust_store->trust_store->AddMTCTrustAnchor(mtc_anchor));
 
   CertificateVerifyOptions opts;
@@ -420,13 +462,17 @@
   // generic_cert_ and leaf_b_ have proofs to subtree ranges with the same start
   // but different ends. Check that CertificateVerify only succeeds if the trust
   // store has the right MTCAnchor.
-  std::vector<TrustedSubtree> trusted_subtrees_a = {generic_cert_subtree_};
-  std::vector<TrustedSubtree> trusted_subtrees_b = {leaf_b_subtree_};
+  std::map<uint16_t, std::vector<TrustedSubtree>> trusted_subtrees_a;
+  trusted_subtrees_a[kLogNumber] = {generic_cert_subtree_};
+  std::map<uint16_t, std::vector<TrustedSubtree>> trusted_subtrees_b;
+  trusted_subtrees_b[kLogNumber] = {leaf_b_subtree_};
 
-  auto mtc_anchor_a = std::make_shared<MTCAnchor>(MakeSpan(kAnchorLogId),
-                                                  MakeSpan(trusted_subtrees_a));
-  auto mtc_anchor_b = std::make_shared<MTCAnchor>(MakeSpan(kAnchorLogId),
-                                                  MakeSpan(trusted_subtrees_b));
+  auto mtc_anchor_a =
+      std::make_shared<MTCAnchor>(MakeSpan(kCaId), SignatureAlgorithm::kMldsa44,
+                                  UpRef(ca_spki_), trusted_subtrees_a);
+  auto mtc_anchor_b =
+      std::make_shared<MTCAnchor>(MakeSpan(kCaId), SignatureAlgorithm::kMldsa44,
+                                  UpRef(ca_spki_), trusted_subtrees_b);
 
   std::unique_ptr<VerifyTrustStore> trust_store_a = EmptyTrustStore();
   ASSERT_TRUE(trust_store_a->trust_store->AddMTCTrustAnchor(mtc_anchor_a));
@@ -462,10 +508,11 @@
 }
 
 TEST_F(VerifyMTCTest, MultipleSubtrees) {
-  std::vector<TrustedSubtree> subtrees = {generic_cert_subtree_,
-                                          leaf_b_subtree_, leaf_c_subtree_};
-  auto mtc_anchor =
-      std::make_shared<MTCAnchor>(MakeSpan(kAnchorLogId), MakeSpan(subtrees));
+  std::map<uint16_t, std::vector<TrustedSubtree>> subtrees;
+  subtrees[kLogNumber] = {generic_cert_subtree_, leaf_b_subtree_,
+                          leaf_c_subtree_};
+  auto mtc_anchor = std::make_shared<MTCAnchor>(
+      MakeSpan(kCaId), SignatureAlgorithm::kMldsa44, UpRef(ca_spki_), subtrees);
   std::unique_ptr<VerifyTrustStore> trust_store = EmptyTrustStore();
   ASSERT_TRUE(trust_store->trust_store->AddMTCTrustAnchor(mtc_anchor));