Skip to content

Conversation

@awoie
Copy link
Collaborator

@awoie awoie commented Dec 19, 2024

This PR updates the session transcript section:

  • refer to OID4VP Annex B

fixes #135 but depends on merging openid/OpenID4VP#374

@tlodderstedt tlodderstedt requested a review from hlozi January 7, 2025 20:28
@c2bo
Copy link
Member

c2bo commented Jan 7, 2025

Missing document history entry

@awoie
Copy link
Collaborator Author

awoie commented Jan 7, 2025

Missing document history entry

fixed

* `clientId` and `nonce` parameters in the Handover MUST be the `client_id` and `nonce` parameters included in the Authorization Request from the Verifier.
* `origin` in the Handover is the origin of the Verifer, obtained from the Web-platform and/or app platform.
* The `SessionTranscript` and `Handover` CBOR structures MUST be generated in accordance with Annex B.3.4.1 of [@!OIDF.OID4VP].
* The hash function used to compute the `OID4VPDCAPIHandoverInfoHash` value in the `OID4VPDCAPIHandover` CBOR structure, as defined in Annex B.3.4.1, MUST be one of the following: SHA-256, SHA-384, SHA-512.
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Not entirely sure about this one, but we are currently only talking about sha-256 in HAIP (currently scoped to sd-jwt vc - https://openid.github.io/oid4vc-haip/openid4vc-high-assurance-interoperability-profile-wg-draft.html#section-9).

Would it make sense to remove that statement about hash functions here and move that into the general section profiling hash functions (perhaps with another PR, not this one)?

Copy link
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I updated the OID4VP PR to allow only SHA-256 since SessionTranscript is not transmitted. I updated this PR to reflect this change. Please review again @c2bo @timcappalli @hlozi @leecam @jogu .

@awoie awoie requested review from c2bo, hlozi and timcappalli January 9, 2025 12:23
@Sakurann Sakurann merged commit aaf1964 into main Jan 15, 2025
2 checks passed
Sakurann pushed a commit that referenced this pull request Jan 28, 2025
5 approvals. open for more than a week. wg approval to merge
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

define sessiontranscript for mdoc profile over DC API

8 participants