Hi all, With SD-JWT now published as RFC 9901 congratulations.
I’d like to flag an individual draft that deliberately applies its selective-disclosure analysis in a neighboring document class: https://datatracker.ietf.org/doc/draft-sabey-succession-receipts-sd/ It applies the salted-digest / disclosure-by-omission mechanism to plain JSON documents canonicalized with JCS (RFC 8785), rather than JWS; the underlying documents are signed receipts of authority succession between AI agents: https://datatracker.ietf.org/doc/draft-sabey-succession-receipts/ The draft is explicit that it composes with SD-JWT rather than replacing or competing with it. I’d particularly value review from this group on whether the security considerations correctly restate RFC 9901’s analysis for the non-JWS setting. A public conformance corpus and an in-browser verifier are available here: https://github.com/jsabes24/css-succession-receipts Thanks, Jaryn Sabey
_______________________________________________ OAuth mailing list -- [email protected] To unsubscribe send an email to [email protected]
