Open-Credentialing-Initiative / Digital-Wallet-Conformance-Criteria

Conformance Criteria for Digital Wallets | https://open-credentialing-initiative.github.io/Digital-Wallet-Conformance-Criteria/latest
https://open-credentialing-initiative.github.io/Digital-Wallet-Conformance-Criteria/latest
Apache License 2.0
1 stars 2 forks source link

LDAP revocation & wallet #67

Open bluesteens opened 1 year ago

bluesteens commented 1 year ago

Steering: Proposal Summary

Used to propose a change or addition to Steering. This is for the Steering work START approval step. Discuss the proposed work or change. Section 4.1.10 Credential Revocation seems to mix issuer and wallet requirements. Suggest to sharpen the focus and clarify the wallet requirements.

Steering: Publication Summary

Used to present completed work to Steering for approval to publish. Discuss the work that was completed in reference to the above proposal. Include any differences from the proposal and why. use [GitHub Preview](https://htmlpreview.github.io/) to show final state of documents along with pull requests (if needed). #


Detailed Description:

observation 1

Section 4.1.10 Credential Revocation says,

Digital Wallet Providers SHALL implement the OCI Directory Service (LDAP)-based mechanism for determining if a Verifiable Credential has been revoked (vc-status-2021-ldap).

This is not precise, as the issuer needs to run LDAP servers, the wallet just needs to be able to call them. Suggest to reword to sth like,

wallet providers shall implement API calls to the LDAP server of the issuer and check the revocation status

observation 2

I'd also remove the intro sentence, as that's hypothetical and not relevant for audits or implementers. They only need to know what applies NOW.

OCI can potentially support multiple methods for communicating when a Credential has been revoked.

observation 3

Further, the para ends with,

Credential Issuer and Digital Identity providers SHALL implement LDAPS, which is LDAP secured by communication over Transport Layer Security (TLS) protocol.

The CI criteria do not belong in the wallet conformance document.


Triage:

Affected Parties (help determine Sunrise/Sunset):

Affected OCI Artifact

Change Category (Guides Steering Review)

- Steering/Industry Review

- Steering/Industry Notification

Communication

bluesteens commented 1 year ago

consider impact on issuer criteria @britpayson

bluesteens commented 1 year ago

relates to https://github.com/Open-Credentialing-Initiative/Digital-Wallet-Conformance-Criteria/issues/76

bluesteens commented 1 year ago

hold until decision on PR #75

bluesteens commented 1 year ago

PR & ticket closed, as merged into https://github.com/Open-Credentialing-Initiative/Digital-Wallet-Conformance-Criteria/issues/76