Skip to content

Consider removing cwt proof type #320

@awoie

Description

@awoie

It would be worth discussing whether we should remove the cwt proof type for the following reasons:

  • The encoding of cwt proofs is not fully specified. I guess it is supposed to be base64url of the COSE_Sign1 structure. But given that nobody complaint about this not being specified, my assumption is that there cannot be many implementers.
  • Even if implementers want to avoid using JOSE in favor of COSE, they won't be able to do that in a lot of cases because they will likely need wallet attestations/oauth attestation-based client authentication that will represent probably the same keys and proofs as JWKs and JWTs. To be clear, I'm not recommending we should add cwt proofs to those drafts.

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions