[OAUTH-WG] Re: [SPICE] Re: OAuth Digital Credential Status Attestations

2024-06-11 Thread Giuseppe De Marco
Ciao Denis, thank you for the time spent in reading and writing, I see several points that express an enormous gratitude from me for your contribution. I add my feedbacks below. Il giorno mar 11 giu 2024 alle ore 18:12 Denis ha scritto: > > The text of the email states: > > "there are several

[OAUTH-WG] Re: [SPICE] Re: OAuth Digital Credential Status Attestations

2024-06-11 Thread Denis
Hi Giuseppe, Orie and Francesco, Here is my feedback about the Status Assertion mechanism. The text of the email states: "there are several use cases for revocations, each of which is addressed, either wholly or partially, in these specifications". While there are indeed several use

[OAUTH-WG] Re: Call for adoption - PIKA

2024-06-11 Thread Giuseppe De Marco
Ciao Tom, Public Key Infrastructure satisfies the requirements to provide public keys. Technically, using X.509 certificates represents a consolidated approach. Giving public keys doesn't help in establishing the trust or fully proving the compliance to shared rules, that's why openid federation

[OAUTH-WG] Re: Call for adoption - PIKA

2024-06-11 Thread Giuseppe De Marco
Hey Richard, My reply was very verbose, thank you for the time spent in reading it. The problem I see in the communities around the openid/ietf/any-other technical specification is the way we use the term trust and how we aim to achieve trust from a technical perspective. I can show that my