Open-Credentialing-Initiative / Digital-Wallet-Conformance-Criteria

Conformance Criteria for Digital Wallets | https://open-credentialing-initiative.github.io/Digital-Wallet-Conformance-Criteria/latest
https://open-credentialing-initiative.github.io/Digital-Wallet-Conformance-Criteria/latest
Apache License 2.0
1 stars 2 forks source link

ambiguous 2FA requirement #7

Closed bluesteens closed 1 year ago

bluesteens commented 2 years ago

Steering summary: Proposal to review the wording and intent regarding the provision of 2FA, as it is unclear whether it is an obligation or optional.


observation:

language definition:

Issue: It is unclear whether SHALL or SHOULD applies to the 2FA/MFA requirement.

Suggestion: If SHOULD is the intention, rephrase 4.3.1 Wallet User Management as follows: "This process SHOULD include secure provisioning of 2FA or MFA access credentials to a given user."

bluesteens commented 1 year ago

suggested rewording of NFR001 Conformance Criteria by C Stöcker:

Authentication

Authorization

bluesteens commented 1 year ago

Triage:

Affected Parties (help determine Sunrise/Sunset):

Affected OCI Artifact

Change Category (Guides Steering Review)

- Steering/Industry Review

- Steering/Industry Notification

bluesteens commented 1 year ago

July, 27: to be released in Digital Wallet Criteria v3.3.0, interop profile v3.2.0