ietf-wg-spice / draft-ietf-spice-sd-cwt

SPICE SD-CWT
https://ietf-wg-spice.github.io/draft-ietf-spice-sd-cwt/intialize-draft-contents/draft-ietf-spice-sd-cwt.html
Other
3 stars 2 forks source link

turn the cnonce in the kbt optional #17

Closed beltram closed 1 month ago

beltram commented 1 month ago

Hi,

this fixes a small inconsistency in the draft since it is stated at the beginning of the draft that To protect against replay attacks, the verifier SHOULD provide a nonce, and reject requests that do not include an acceptable an nonce (cnonce). This guidance can be ignored in cases where replay attacks are mitigated at another layer.

There are two options here: either turn the claim optional or have the Holder use a fixed nonce in case he did not get one from the Verifier. I prefer the former.

Thoughts ?