You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
there's a european PID type "urn:ec.eu.x.y.z" and a national type "urn:de.bla" that extends "urn:ec.eu.x.y.z"
a rogue issuer issues a credential "urn:attacker" that extends either "urn:ec.eu.x.y.z" or "urn:ec.eu.x.y.z"
it is now important that verifiers/wallets don't accept these credentials. the fact that someone issued a credential extending a known type does not imply that they are allowed to do so (or that they are a valid issuer at all)
This should be captured in a security consideration, ideally also in processing rules.
The text was updated successfully, but these errors were encountered:
Example:
This should be captured in a security consideration, ideally also in processing rules.
The text was updated successfully, but these errors were encountered: