Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

clarify issuer can be an AS too #451

Open
wants to merge 1 commit into
base: main
Choose a base branch
from
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion openid-4-verifiable-credential-issuance-1_0.md
Original file line number Diff line number Diff line change
Expand Up @@ -84,7 +84,7 @@ Presentation:
: Data that is presented to a specific Verifier, derived from one or more Verifiable Credentials that can be from the same or different Credential Issuers. It can be of any Credential Format.

Credential Issuer (or Issuer):
: An entity that issues Verifiable Credentials. In the context of this specification, the Credential Issuer acts as an OAuth 2.0 Resource Server (see [@!RFC6749]).
: An entity that issues Verifiable Credentials. In the context of this specification, the Credential Issuer acts as an OAuth 2.0 Authorization Server and/or a Resource Server (see [@!RFC6749]).
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

IMHO, specification currently provides a clear definition that Credential Issuer is, first and foremost, a Resource Server, and it took some time (drafts) to de-associate Issuer from AS (updated sequence diagrams, removed c_nonce from token endpoint etc).

The fact that a Credential Issuer could also act a an AS (protecting itself) is an implementation detail and as such, perhaps related remark to the implementation consideration section could me add (keeping the current definition as is).


Holder:
: An entity that receives Verifiable Credentials and has control over them to present them to the Verifiers as Presentations.
Expand Down
Loading