International-Data-Spaces-Association / InformationModel

The Information Model of the International Data Spaces implements the IDS reference architecture as an extensible, machine readable and technology independent data model.
Apache License 2.0
61 stars 35 forks source link

Question about connector identity #465

Closed DominikPinsel closed 3 years ago

DominikPinsel commented 3 years ago

Hello everyone,

I've a question regarding the DAPS and the Identity Provider interplay.

The Information Model says

My questions would be:

sub> Dominik Pinsel <dominik.pinsel@daimler.com, Daimler TSS GmbH, legal info/Impressum

juliapampus commented 3 years ago

@gbrost @sebbader

gbrost commented 3 years ago

Hi,

  1. Yes, each connector has its own identity (X.509 certificate & private key).
  2. The connector provides its setf description and there we have the link to the participant.

Best Gerd

MoritzKeppler commented 3 years ago

thx! But the self description isn't something a caller can trust, right? It's not signed/certified somehow. Wouldn't it be better if the link to the participant is included in the DAT token? question is maybe related to #259 Moritz Keppler moritz.keppler@daimler.com, Daimler TSS GmbH, legal info/Impressum

gbrost commented 3 years ago

Good point and possibly a desirable feature. But this is not part of the reality yet. The idea was to verify the identity also with the identity certificate for each device. There you have a link to the organisation. However, just a link via the subject and not a specific link to a participant URI at the ParIS. I will open an issue for ids-g.

DominikPinsel commented 3 years ago

Thanks for the quick responses. Once again learned a lot. On my part this question is answered and the issue resolved 👍

sub> Dominik Pinsel <dominik.pinsel@daimler.com, Daimler TSS GmbH, legal info/Impressum