w3c / wot-discovery

Repository for WoT discovery discussion
https://w3c.github.io/wot-discovery/
Other
19 stars 17 forks source link

Consider how to sign TDs in a directory service #24

Open mmccool opened 4 years ago

mmccool commented 4 years ago

See discussion here: https://github.com/w3c/wot-security/issues/166 If TDs are not internally signed, we may still want to "envelope" them when we return them from a directory service.

mmccool commented 4 years ago

We also need to design directories so that signed TDs do not have their source signatures invalidated. That means directories can't add or remove things from source-signed TDs.

mmccool commented 3 years ago

I created a PR to add an LD-PROOF section to TDs (see https://github.com/w3c/wot-thing-description/pull/943) but we should discuss with DID to know when/if that spec will make it to REC status.

mmccool commented 1 year ago

waiting for JSON-LD and RDF signatures, so have to defer this