Re: [OAUTH-WG] Clarification on SD-JWT verification

2023-10-20 Thread Brian Campbell
Agree that it should be clarified. Being precise with language around this stuff is tricky. But my understanding of the intent was to ensure that no digest value is repeated in the whole of the SD-JWT - either in the payload directly or recursively in any Disclosure. Because of the trickiness of la

Re: [OAUTH-WG] Clarification on SD-JWT verification

2023-10-20 Thread Daniel Fett
Hi Jacob, the intention was to cover the first case you listed. We should clarify this. -Daniel Am 20.10.23 um 15:02 schrieb Jacob Ward: Hello again, On a similar note to my previous email, could I get some clarity on a step in the SD-JWT verification process? /4. If any digests were fou

[OAUTH-WG] Clarification on SD-JWT verification

2023-10-20 Thread Jacob Ward
Hello again, On a similar note to my previous email, could I get some clarity on a step in the SD-JWT verification process? *4. If any digests were found more than once in the previous step, the SD-JWT MUST be rejected.* Step 4 in Section 6.1 (as shown above) could have multiple meanings in my