OIDF-automation

Results 218 comments of OIDF-automation

### Imported from AB/Connect bitbucket - Original Commenter: dzagidulin Forgot to add - it’s worth highlighting that VPs are for \(optionally\) authenticating the _presenter_, who doesn’t have to be the...

### Imported from AB/Connect bitbucket - Original Commenter: dwc8 The other benefit is that the VP stops replay attacks, by the Holder including the nonce presented by the RP into...

### Imported from AB/Connect bitbucket - Original Commenter: KristinaYasuda thank you! super helpful! How does the RP know when it needs to verify holder binding and when it does not...

### Imported from AB/Connect bitbucket - Original Commenter: dzagidulin So I think there’s two questions there - 1\) how does the RP know when it wants to verify holder binding,...

### Imported from AB/Connect bitbucket - Original Commenter: KristinaYasuda Thanks, Dmitri! agreed on the first point! On the second point, OpenID4VP uses Presentation exchange as a query language so guess...

### Imported from AB/Connect bitbucket - Original Commenter: KristinaYasuda especially with the credentials that use claim-based binding and not cryptographic binding, it should be possible to return VC that is...

### Imported from AB/Connect bitbucket - Original Commenter: danielfyes I stumbled upon the same issue when reviewing the VP spec. There should be room for “presentations” without holder binding. One...

### Imported from AB/Connect bitbucket - Original Commenter: KristinaYasuda from the security analysis: > **PROBLEM:** If no holder binding is used, right now, there is no way to transport the...

### Imported from AB/Connect bitbucket - Original Commenter: KristinaYasuda SIOP call. discussed to keep the language in the spec text saying the currently \(ID-2\) OID4VP operates under the assumption that...

### Imported from AB/Connect bitbucket - Original Commenter: KristinaYasuda regarding holder binding mechanisms other than cryptographic,@{63696ff6c383ad8421462592} said “i think the ISO approach does makes sense to me. meaning, issuer says...