Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[VC Security & Trust Document] Improve Security Requirement W-01 #14

Open
Macke opened this issue Aug 10, 2023 · 0 comments
Open

[VC Security & Trust Document] Improve Security Requirement W-01 #14

Macke opened this issue Aug 10, 2023 · 0 comments

Comments

@Macke
Copy link

Macke commented Aug 10, 2023

Imported from AB/Connect bitbucket: https://bitbucket.org/openid/connect/issues/2016

Original Reporter: danielfett

Kristina Yasuda

2023-02-28

it should be explained why the focus is only on protocol and credential formats. technically, entity identifiers (DIDs, jwk thumbprints, etc.) are not part of credential format or protocol, but is crucial part of security, no? if entity identifier was considered as part of credential format it should be explicit.

secure implementations of cryptographic algorithms, the use of secure random number generators, the secure use of hardware-based storage

I have only seen sd-jwt define some of these… W3C VCDM definitely does not and not even mDL spec itself mandates HW-based storage.

something like implement securely and correctly as required by a trust framework would cover the introductory text better..

@danielfett danielfett removed bug Something isn't working major labels Aug 14, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants