tlodderstedt / openid-connect-4-credential-issuance

Specification to allow holders to request issuance of credentials and issuers to issue verifiable credentials.
7 stars 1 forks source link

Security Considerations #17

Open tlodderstedt opened 2 years ago

tlodderstedt commented 2 years ago

some DIDs allow you to register keys without checking whether you control that key or not. with some DID methods, even if you have a DID, you will not be able to generate signature.

at least add this to the security considerations:

Issuer needs to be careful to which DID methods they issued credentials to