Skip to content

Issuer-signed JWT Verification Key Validation - Separation of signature and identity verification/validation? #253

@alenhorvat

Description

@alenhorvat

There seem to be several mechanisms for issuer key validation (section 3.5).

Two mechanisms define fetching of keys (issuer metadata, DID), and one can be embedded or referenced (x509).

Would it make sense to enable signature validation at all times and

Public key - identity binding can be verified

kid could be misused to express the validation mechanism or one could define an additional header claim where identity verification mechanism is specified:

  • calling the /.well-known/jwt-vc-issuer
  • resolving a DID
  • using Federation ...
  • ...

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions