Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Should Status lists be used for the validation of attestations? #306

Open
vilmosa opened this issue Sep 3, 2024 · 0 comments
Open

Should Status lists be used for the validation of attestations? #306

vilmosa opened this issue Sep 3, 2024 · 0 comments

Comments

@vilmosa
Copy link

vilmosa commented Sep 3, 2024

According to the eIDAS 2 regulation "Relying Parties shall be responsible for carrying out the procedure for authenticating and validating person identification data and electronic attestation of attributes requested from European Digital Identity Wallets". According to the ARF there are status list which will facilitate the validation. However these lists cannot be reached if RPs are offline, therefore in such transactions the technical conditions for validation are missing. The use of status lists does not comply with the legal requirements.
Alternative methods should be used which can better guarantee the validity and integrity of PIDs and attestations. A trust chain from provider through user to verifier would be a more suitable solution.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant