define Attack Potential Resistance values in key attestation
Open
Nobody has claimed this yet.
EUDIW
- Dominant language
- No language data
- Stars
- 125
- Forks
- 41
- PR merge metrics
- No merged PRs in 30d
Description
How can one know that `the value does not map to a well-known specification`? Some IETF specs (e.g. Web Linking and link relations) mandate that *any* non-standard value must be an URI (e.g. https://www.rfc-editor.org/rfc/rfc8288.html#section-2.1.2). I suggest a similar approach here.
Originally posted by @pmhsfelix in https://github.com/openid/OpenID4VCI/pull/389#discussion_r1842458096
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reviewing the concern in the linked pull-request discussion and the cited RFC 8288 section on non-standard values. The issue is resolved when the key-attestation specification clearly defines how Attack Potential Resistance values that do not map to a well-known specification must be represented.
Written by the indexing model from the issue text.
Assessment
- Domain
- authentication, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100