In reading through the spec there is specific language around Holders and 
Verifiers including in some cases MUSTs if a Delegate Holder is presenting to a 
Verifier. Is there a reason why the delegate SD-JWT can’t be a generic 
delegation mechanism and not have Holder/Verifier semantics?

In seems really useful to have a structure that can be received by WorkloadA, 
and then sent on by WorkloadA to WorkloadB where WorkloadA selectively 
discloses some received in the original SD-JWT and then adds it’s own 
additional selective disclosure claims (unique to WorkloadA) so that WorkloadB 
receives a dSD-JWT which selectable disclosed claims from both the Issuer and 
WorkloadA. Workload B can repeat the process to WorkloadC, etc.

Is there a reason this mechanism can’t be generalized?

Thanks,
George

--
George Fletcher
Practical Identity LLC
_______________________________________________
OAuth mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to