In reading through the spec there is specific language around Holders and Verifiers including in some cases MUSTs if a Delegate Holder is presenting to a Verifier. Is there a reason why the delegate SD-JWT can’t be a generic delegation mechanism and not have Holder/Verifier semantics?
In seems really useful to have a structure that can be received by WorkloadA, and then sent on by WorkloadA to WorkloadB where WorkloadA selectively discloses some received in the original SD-JWT and then adds it’s own additional selective disclosure claims (unique to WorkloadA) so that WorkloadB receives a dSD-JWT which selectable disclosed claims from both the Issuer and WorkloadA. Workload B can repeat the process to WorkloadC, etc. Is there a reason this mechanism can’t be generalized? Thanks, George -- George Fletcher Practical Identity LLC _______________________________________________ OAuth mailing list -- [email protected] To unsubscribe send an email to [email protected]
