Skip to content

Commit d915ccf

Browse files
awoiedanielfettbc-pi
authored
Revert changes from PR #251 (#278)
* fix: reverted changes in PR#251 * fix: change doc history entry * Update draft-ietf-oauth-sd-jwt-vc.md Co-authored-by: Daniel Fett <[email protected]> * Update draft-ietf-oauth-sd-jwt-vc.md --------- Co-authored-by: Daniel Fett <[email protected]> Co-authored-by: Brian Campbell <[email protected]>
1 parent 2d51367 commit d915ccf

File tree

1 file changed

+39
-1
lines changed

1 file changed

+39
-1
lines changed

draft-ietf-oauth-sd-jwt-vc.md

+39-1
Original file line numberDiff line numberDiff line change
@@ -343,7 +343,7 @@ obtain the public key using JWT VC Issuer Metadata as defined in (#jwt-vc-issuer
343343
- X.509 Certificates: If the recipient supports X.509 Certificates and the `iss` value contains an HTTPS URI, the recipient MUST
344344
1. obtain the public key from the end-entity certificate of the certificates from the `x5c` header parameter of the Issuer-signed JWT and validate the X.509 certificate chain accordingly, and
345345
2. ensure that the `iss` value matches a `uniformResourceIdentifier` SAN entry of the end-entity certificate or that the domain name in the `iss` value matches the `dNSName` SAN entry of the end-entity certificate.
346-
346+
- DID Document Resolution: If a recipient supports DID Document Resolution and if the `iss` value contains a DID [@W3C.DID], the recipient MUST retrieve the public key from the DID Document resolved from the DID in the `iss` value. In this case, if the `kid` JWT header parameter is present, the `kid` MUST be a relative or absolute DID URL of the DID in the `iss` value, identifying the public key.
347347
Separate specifications or ecosystem regulations MAY define rules complementing the rules defined above, but such rules are out of scope of this specification. See (#ecosystem-verification-rules) for security considerations.
348348

349349
If a recipient cannot validate that the public verification key corresponds to the `iss` value of the Issuer-signed JWT, the SD-JWT VC MUST be rejected.
@@ -1204,6 +1204,43 @@ recommendations in (#robust-retrieval) apply.
12041204
</front>
12051205
</reference>
12061206

1207+
<reference anchor="W3C.DID" target="https://www.w3.org/TR/did-core/">
1208+
<front>
1209+
<author initials="M." surname="Sporny" fullname="Manu Sporny">
1210+
<organization>
1211+
<organizationName>Digital Bazaar</organizationName>
1212+
</organization>
1213+
</author>
1214+
<author initials="D." surname="Longley" fullname="Dave Longley">
1215+
<organization>
1216+
<organizationName>Digital Bazaar</organizationName>
1217+
</organization>
1218+
</author>
1219+
<author initials="M." surname="Sabadello" fullname="Markus Sabadello">
1220+
<organization>
1221+
<organizationName>Danube Tech</organizationName>
1222+
</organization>
1223+
</author>
1224+
<author initials="D." surname="Reed" fullname="Drummond Reed">
1225+
<organization>
1226+
<organizationName>Evernym/Avast</organizationName>
1227+
</organization>
1228+
</author>
1229+
<author initials="O." surname="Steele" fullname="Orie Steele">
1230+
<organization>
1231+
<organizationName>Transmute</organizationName>
1232+
</organization>
1233+
</author>
1234+
<author initials="C." surname="Allen" fullname="Christopher Allen">
1235+
<organization>
1236+
<organizationName>Blockchain Commons</organizationName>
1237+
</organization>
1238+
</author>
1239+
<title>Decentralized Identifiers (DIDs) v1.0</title>
1240+
<date day="19" month="July" year="2022"/>
1241+
</front>
1242+
</reference>
1243+
12071244
<reference anchor="W3C.VCDM" target="https://www.w3.org/TR/vc-data-model-2.0/">
12081245
<front>
12091246
<author initials="M." surname="Sporny" fullname="Manu Sporny">
@@ -1533,6 +1570,7 @@ for their contributions (some of which substantial) to this draft and to the ini
15331570

15341571
-07
15351572

1573+
* Revert change from previous release that removed explicit mention of DIDs in the Issuer-signed JWT Verification Key Validation section
15361574
* Remove the requirement to insert a .well-known part for vct URLs
15371575
* fix section numbering in SD-JWT references to align with the latest -14 version
15381576

0 commit comments

Comments
 (0)