-
Notifications
You must be signed in to change notification settings - Fork 15
Remove now incorrect sentence about iss in SD-JWT VC #216
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
| * The Issuer MUST NOT make any of the JWT Claims in the table above to be selectively disclosable, so that they are always present in the SD-JWT-VC presented by the Holder. | ||
| * It is at the discretion of the Issuer whether to use `exp` claim and/or a `status` claim to express the validity period of an SD-JWT-VC. The Wallet and the verifier MUST support both mechanisms. | ||
| * The `iss` claim MUST be an HTTPS URL. The `iss` value is used to obtain Issuer’s signing key as defined in (#issuer-key-resolution). | ||
| * The `iss` claim MUST be an HTTPS URL. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I would remove this requirement. Especially, since iss can be really confusing if the actual and verified issuer information is provided by x5c. Perhaps we would even need some language that says that.
| * The `iss` claim MUST be an HTTPS URL. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I opened #215 for this - I do think we need a working group discussion on that topic, whereas removing the now incorrect sentence is hopefully straightforward.
Sakurann
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
i don't understand why the sentence being removed is inconsistent with the spec text? #issuer-key-resolution section still exists and defines how to obtain issuer key to validate sd-jwt vc. what's wrong with pointing to it?
The key resolution section says to use only the |
awoie
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Approving but we need to address #215
x5c is required as per #178
This leaves it unsaid what iss is actually set to. I raised #215
in case we need to say something about that but think the scope of this PR should just be removing the text that is now inconsistent with other parts of HAIP.