[Openid-dcp] Minutes for 2026-07-15 DCP WG meeting
Frederik Krogsdal Jacobsen
frederik.krogsdal at idura.eu
Wed Jul 15 09:06:17 UTC 2026
- Participants: Frederik Krogsdal Jacobsen, Christian Bormann, Dima
Postnikov, Martijn Haring, Joseph Heenan
- Conformance tests
- Many people have run the test suite and confirmed that they work:
every test suite has been run by several organizations.
- All identified issues have been addressed, but we should still
expect that improvements may be made in the future anyway as issues are
found.
- Ask of the working group is to confirm that the test suite is ready
for certification use.
- Note: the test suite is mostly for the OpenID4VC protocol-level
things, it does not fully test credential format implementations. It only
tests e.g. that mdoc session transcripts are correctly generated because
this is specified in OpenID specifications. This is communicated, but we
should continue to be very clear on this in public communication.
- Observation: since the tests mostly test protocol-level properties,
combining results for the different credential formats is reasonable.
- No concerns were raised in the meeting. The working group would
like the public communications for approval before announcing the
certification, primarily to make sure the scope of the test suite is
appropriately communicated.
- OpenID4VP
- https://github.com/openid/OpenID4VP/issues/718
- The problem is whether it is allowed to return claims that were
not requested. The main issue is that mdoc defines logic that
forces you to
do this on age_over_xx claims.
- Martijn: The age_over_xx logic in mdoc was defined because there
was no general query language at the time. It is not
necessarily the best
way, but now it’s locked into the ISO standard, so we have to
do something.
- The current text seems to forbid returning claims that were not
requested, but is this the case? Not 100% clear from the text.
- Martijn: Are you allowed to return claims as device signed
items? The text needs to be clarified.
- Paul: Doing these kinds of range proofs (age_over_xx returning
other claims) is not supported by the technology yet.
- Joseph: The claims should probably be returned as issuer signed
items.
- Joseph: The age_over_xx definition is part of the mdl format,
not the mdoc definition. It is not part of the query language
definition.
The ago_over_xx behaviour isn’t part of the -5 query language
definition
(i.e. their equivalent of DCQL).
- Frederik: There is a lack of clarity on the difference between
“real” claims (that contain the info we want) and claims that
only exist
for technical reasons. We need to define some language that
lets us refer
to these things precisely, also for e.g. credential versioning.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openid.net/pipermail/openid-specs-digital-credentials-protocols/attachments/20260715/660782c4/attachment.htm>
More information about the Openid-specs-digital-credentials-protocols
mailing list