Closed
Description
Following up on the conversations some of us had after IIW (see openid/OpenID4VCI#71 (comment)), this issue proposes the addition of a server provided nonce mechanism to limit the lifetime of a Client Attestation PoP JWT, similar to the DPoP nonce mechanism.
This relates to openid/OpenID4VCI#71, however the required changes need to be addressed on the attestation spec and not on the VCI spec.
I'm currently working on a PR to add this.
Metadata
Metadata
Assignees
Labels
No labels