-
Notifications
You must be signed in to change notification settings - Fork 37
Closed
Labels
Description
It would be worth discussing whether we should remove the cwt proof type for the following reasons:
- The encoding of
cwtproofs is not fully specified. I guess it is supposed to be base64url of the COSE_Sign1 structure. But given that nobody complaint about this not being specified, my assumption is that there cannot be many implementers. - Even if implementers want to avoid using JOSE in favor of COSE, they won't be able to do that in a lot of cases because they will likely need wallet attestations/oauth attestation-based client authentication that will represent probably the same keys and proofs as JWKs and JWTs. To be clear, I'm not recommending we should add
cwtproofs to those drafts.
babisRoutis, sietseringers, bc-pi, paulbastian, mickrau and 1 morebc-pibc-pibc-pi