There seem to be several mechanisms for issuer key validation (section 3.5).
Two mechanisms define fetching of keys (issuer metadata, DID), and one can be embedded or referenced (x509).
Would it make sense to enable signature validation at all times and
Public key - identity binding can be verified
kid could be misused to express the validation mechanism or one could define an additional header claim where identity verification mechanism is specified:
- calling the /.well-known/jwt-vc-issuer
- resolving a DID
- using Federation ...
- ...