-
Notifications
You must be signed in to change notification settings - Fork 21
Data Integrity -> external resources #323
Copy link
Copy link
Open
Labels
editorialThis issue or PR constitutes an editorial change.This issue or PR constitutes an editorial change.futuresecurity-trackerGroup bringing to attention of security, or tracked by the security Group but not needing response.Group bringing to attention of security, or tracked by the security Group but not needing response.
Metadata
Metadata
Assignees
Labels
editorialThis issue or PR constitutes an editorial change.This issue or PR constitutes an editorial change.futuresecurity-trackerGroup bringing to attention of security, or tracked by the security Group but not needing response.Group bringing to attention of security, or tracked by the security Group but not needing response.
Type
Fields
Give feedbackNo fields configured for issues without a type.
Dear,
the following references that some issuer are using in the VCs are NOT available, meaning that verification of those credentials is impossible if the contexts are not stored locally by the verifier.
Furthermore, if the verifier wants to include them, the references cannot be easily found.
References:
https://w3c-ccg.github.io/did-resolution/contexts/did-resolution-v1.json
https://w3id.org/did-resolution/v1
This is a critical issue for the signature design. I urge the authors to consider defining a method of how the contexts CAN/SHOULD/MUST be included in the protected or unprotected signature part and what are the rules for 3rd parties hosting the contexts to ensure longevity.
Thank you for your understanding.
Alen