Skip to content

Reader authentication x509 certificate header - #65

Open
martijnharing wants to merge 1 commit into
mainfrom
issue-51-readerauth_x5chain_header
Open

martijnharing wants to merge 1 commit into
mainfrom
issue-51-readerauth_x5chain_header

Conversation

@martijnharing

Copy link
Copy Markdown
Collaborator

Resolves #51
Added section on public key authentication methods, specifically X.509 certificates, and their inclusion in COSE_Signature structure.

Resolves #51 
Added section on public key authentication methods, specifically X.509 certificates, and their inclusion in COSE_Signature structure.
github-actions Bot pushed a commit that referenced this pull request Oct 5, 2026
@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown

📄 Editor's Copy preview

https://openid.github.io/dchp/PREVIEW-DO-NOT-USE/pr-65/digital-credentials-harmonized-presentation-editors-copy.html

Preview of cdb307d; updated on every push. For review only — the official specifications are published at https://openid.net/specs/

@jogu
jogu requested review from andprian and c2bo October 5, 2026 14:43
@jogu

jogu commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Discussed on today's WG call; no feedback, Christian & Andreea offered to review.

Some discussions about the use of the terms verifier vs reader - Matt offered to open an issue on that, that's #67

## Public key authentication ##

This document specifies the following methods to authenticate the public key used for reader authentication:
- X.509 certificate

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

needs another empty line to render properly

Suggested change
- X.509 certificate
- X.509 certificate


Other mechanisms may be used and are out of scope of this document.

When using an X.509 certificate to authenticate the reader authentication public key, that certificate shall be included as an x5chain element in the protected header of the COSE_Signature structure. The x5chain element shall contain at least 1 certificate and may contain more. The x5chain element is defined in RFC 9360.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Since we are using COSE_Sign, we should probably allow multiple signatures here and reformulate a bit?

Suggested change
When using an X.509 certificate to authenticate the reader authentication public key, that certificate shall be included as an x5chain element in the protected header of the COSE_Signature structure. The x5chain element shall contain at least 1 certificate and may contain more. The x5chain element is defined in RFC 9360.
When using an X.509 certificate to authenticate the reader authentication public key, that certificate shall be included as an x5chain element in the protected header of the COSE_Signature structure whose signature is verified with that public key.
The x5chain element shall contain at least one certificate, encoded and ordered as specified in RFC 9360. The first certificate shall contain the reader authentication public key.


## Public key authentication ##

This document specifies the following methods to authenticate the public key used for reader authentication:

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
This document specifies the following methods to authenticate the public key used for reader authentication:
This document specifies the following methods to convey the public key used for reader authentication:

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I suggest convey , since the main idea here is that the reader public key is transported in a certificate.
In other cases we could transport it in other type of signed attestations, while still using X509 certificates to authenticate those attestations.


Other mechanisms may be used and are out of scope of this document.

When using an X.509 certificate to authenticate the reader authentication public key, that certificate shall be included as an x5chain element in the protected header of the COSE_Signature structure. The x5chain element shall contain at least 1 certificate and may contain more. The x5chain element is defined in RFC 9360.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
When using an X.509 certificate to authenticate the reader authentication public key, that certificate shall be included as an x5chain element in the protected header of the COSE_Signature structure. The x5chain element shall contain at least 1 certificate and may contain more. The x5chain element is defined in RFC 9360.
When using an X.509 certificate to convey the reader authentication public key, that certificate shall be included as an x5chain element in the protected header of the COSE_Signature structure. The x5chain element shall contain at least 1 certificate and may contain more. The x5chain element is defined in RFC 9360.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Define x.509 mechanism for verifier authentication

4 participants