Skip to content

Is c_nonce required in proof or not? #331

@awoie

Description

@awoie

Nonces in proof types are OPTIONAL but the following sentence confused me:

The proof element MUST incorporate the Credential Issuer Identifier (audience), and a c_nonce value generated by the Authorization Server or the Credential Issuer to allow the Credential Issuer to detect replay.

It says MUST ..., and a c_nonce. Does that MUST refer to c_nonce as well? Isn't this conflicting with the optionality of nonces in proofs? If it is not conflicting then it is at least confusing.

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions