italia / eudi-wallet-it-docs

Italian EUDI Wallet Technical Specifications
Creative Commons Zero v1.0 Universal
56 stars 20 forks source link

Credential Issuer SHALL revoke attestation for technical security reasons #456

Closed m-basili closed 1 week ago

m-basili commented 1 month ago

In ARF Annex II, VCR_04 states that: "A PID Provider or Attestation Provider SHALL revoke a PID or attestation at least when its security has been compromised", while in the Section Credential Lifecycle the requirement is only recommended: "The Credential Issuers, for technical security reasons (e.g. in the case of compromised cryptographic keys), SHOULD decide to revoke the Credentials." Could we make it mandatory as indicated in Annex II?