oauth-wg / oauth-selective-disclosure-jwt

https://datatracker.ietf.org/doc/draft-ietf-oauth-selective-disclosure-jwt/
Other
57 stars 31 forks source link

The definition of the SD-JWT+KB structure needs to be reworded #490

Closed Denisthemalice closed 2 weeks ago

Denisthemalice commented 2 weeks ago

Item 2 from Section 1.1. (Feature Summary) states:

  1. SD-JWT+KB is a composite structure enabling cryptographic key binding when presented to the Verifier. It comprises the following:

    • (...)
    • (...)
    • A format extending the SD-JWT format for the combined transport of the SD-JWT and the KB-JWT

This description is not understandable.

Change the last bullet into:

   *  A format for the combined transport of a SD-JWT + Sel.Claims 
      and a KB-JWT that includes a hash value computed over the two previous fields