Skip to content

Referencing ISO 18013-7 in OpenID4VP is problematic #519

@TimoGlastra

Description

@TimoGlastra

OpenID4VP latest draft refers to ISO 18013-7, which in turn refers to OpenID4VP ID2

As an implementer I think it's really problematic that OpenID4VP 1.0 will point to a spec (ISO 18013-7), that requires usage of OpenID4VP second implementers draft, which also mandates PEX and a lot of features that have changed since that draft was published.

It will make mDOC over OpenID4VP without DC-API basically impossible to support for implementers targeting OpenID4VP 1.0 (if you're not using the DC-API).

The text currently reads that you need to use 18013-7 to support mDOC without DC-API, which requires supporting an older draft version of OpenID4VP (with PEX!). Changing this behaviour post 1.0 will mean it's a breaking change and thus not possible.

I propose any references to ISO 18013-7 are removed before 1.0 is published. Ideally we add the missing piece for doing mDOC without 18013-7 before 1.0 (i think fixing #402 should be enough), but otherwise leaving it unspecified is better than referencing 18013-7.

Metadata

Metadata

Labels

Type

No type

Projects

No projects

Relationships

None yet

Development

No branches or pull requests

Issue actions