[Openid-dcp] Minutes from 4-Jun-26 DCP WG call
Frederik Krogsdal Jacobsen
frederik.krogsdal at idura.eu
Thu Jun 4 16:01:22 UTC 2026
- Attendees: Paul Bastian (exceptionally chairing the meeting due chair
unavailability), Bjorn Hjelm, Frederik Krogsdal Jacobsen, George Fletcher,
Jan Vereecken, Ryan Galluzzo, Paul Grassi, Christian Bormann, Martijn
Haring, Peter Sorotokin, Rajvardhan Deshmukh, Niels Klomp
- OpenID4VP
- Pull requests:
- https://github.com/openid/OpenID4VP/pull/735
- Frederik to re-review.
- Jan and Christian volunteer to review.
- https://github.com/openid/OpenID4VP/pull/730
- Got several approvals on the call.
- Needs reviews from people who requested changes: Joseph and
Mike Jones.
- https://github.com/openid/OpenID4VP/pull/726
- We need reviews. In particular, we need to make sure there
are no normative changes to SD-JWT VC.
- Jan and Frederik volunteer to review.
- https://github.com/openid/OpenID4VP/pull/719
- Nobody voiced any concerns about Oliver’s proposed text,
except the already existing comment from Frederik.
- The term “opaque” was subject to discussion, and we at some
point decided not to use it. However, the HTML spec
defines “Opaque origin”
to mean what we want, so we are now using the term
“opaque” to conform with
the existing specification.
- Christian will coordinate with Oliver to make changes to the
PR.
- Issues marked 1.1:
- https://github.com/openid/OpenID4VP/issues/634
- Might become irrelevant if the unsigned request is removed
from DC API. But it is not decided whether that will happen yet.
- https://github.com/openid/OpenID4VP/issues/723
- Needs comments.
- OpenID4VCI
- Pull requests:
- https://github.com/openid/OpenID4VCI/pull/736
- Paul and Christian presented the idea at OAuth Security
Workshop, and it was well received. The wider audience did
not think that
any changes need to be made to add features from IAE to FiPA.
- Paul: We should add an overview of what the profile does in
the beginning.
- Regarding the optionality of support, we should clarify the
intention. In particular:
- Is it optional for both issuer and wallet, or just one?
- Should specific interaction types be mandatory if you do
support interactive authorization?
- What should we do in HAIP?
- What should we guide ecosystems to do?
- Paul: interactive authorization makes presentation during
issuance more secure, so it could make sense to require
doing that in HAIP.
- Martijn: It seems weird to mandate presentation in the
issuance specification.
- George: The VCI environment has a very different
interpretation of redirecting to the web than FiPA. So we
should define our
own interaction type to avoid confusion.
- There was some discussion about whether the mapping of error
codes to FiPA is correct. Some of this may be an issue to
be discussed in
FiPA itself. Paul will open an issue in FiPA.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openid.net/pipermail/openid-specs-digital-credentials-protocols/attachments/20260604/3b5af7df/attachment.htm>
More information about the Openid-specs-digital-credentials-protocols
mailing list