Skip to content

Security considerations: Clarify audience values treatment in DC API #541

@jogu

Description

@jogu

From draft Stuttgart security analysis:

Section 14.1.2 and DC API: [OID4VP draft 24, Section 14.1] should be updated to incorporate OID4VP
over the DC API. Paragraph 3, for example, says that the audience value must be the client ID but
in this case the audience value is always the origin asserted by the DC API.

(I think there was some discussion already about splitting out security considerations for DC API & non-DC API cases... if anyone has the issue handy please add it!)

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Relationships

None yet

Development

No branches or pull requests

Issue actions