eu-digital-identity-wallet / eudi-doc-architecture-and-reference-framework

The European Digital Identity Wallet
https://eu-digital-identity-wallet.github.io/eudi-doc-architecture-and-reference-framework/
Other
369 stars 55 forks source link

[Annex 2] Attestation Providers supposed to be trustworthy by default #207

Open peppelinux opened 4 days ago

peppelinux commented 4 days ago

In https://github.com/eu-digital-identity-wallet/eudi-doc-architecture-and-reference-framework/blob/main/docs/annexes/annex-2/annex-2-high-level-requirements.md, ISSU_34, we read

PID Providers, QEAA Providers, and PuB-EAA Providers are supposed to be trustworthy by default.

What it is supposed to mean by default in the field of the trust evaluation mechanisms?

Only the trusted list, and therefore the Trust Anchors contained in it, can be considered trustworthy over all (and therefore might be this considered "by-default").

How a Wallet Instance could consider an Attestation Provider trustworthy by default?