Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Consider how to sign TDs in a directory service #24

Open
mmccool opened this issue May 18, 2020 · 3 comments
Open

Consider how to sign TDs in a directory service #24

mmccool opened this issue May 18, 2020 · 3 comments
Labels
DID JSON-LD Security security-tracker Group bringing to attention of security, or tracked by the security Group but not needing response.

Comments

@mmccool
Copy link
Contributor

mmccool commented May 18, 2020

See discussion here: w3c/wot-security#166
If TDs are not internally signed, we may still want to "envelope" them when we return them from a directory service.

@mmccool
Copy link
Contributor Author

mmccool commented Jun 1, 2020

We also need to design directories so that signed TDs do not have their source signatures invalidated. That means directories can't add or remove things from source-signed TDs.

@mmccool
Copy link
Contributor Author

mmccool commented Sep 7, 2020

I created a PR to add an LD-PROOF section to TDs (see w3c/wot-thing-description#943) but we should discuss with DID to know when/if that spec will make it to REC status.

@mmccool mmccool added the DID label Sep 7, 2020
@mmccool mmccool added Security security-tracker Group bringing to attention of security, or tracked by the security Group but not needing response. labels Nov 16, 2020
@mmccool
Copy link
Contributor Author

mmccool commented Aug 22, 2022

waiting for JSON-LD and RDF signatures, so have to defer this

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
DID JSON-LD Security security-tracker Group bringing to attention of security, or tracked by the security Group but not needing response.
Projects
None yet
Development

No branches or pull requests

1 participant