Skip to content

feat (arch): Verifier provider and Verifier Instances - #72

Open
peppelinux wants to merge 5 commits into
mainfrom
ralph
Open

peppelinux wants to merge 5 commits into
mainfrom
ralph

Conversation

@peppelinux

@peppelinux peppelinux commented Sep 17, 2026 •

Copy link
Copy Markdown
Member

This PR resolves #60 by adding openid_verifier_provider and profiling OpenID4VP Verifier Attestation JWTs for POS / proximity reader instances.

iss is the Provider (Trust Chain); sub is the Organizational Credential Verifier; cnf is the per-instance key.

Instance constraints may narrow organizational entitlements and must not expand them. No new OpenID4VP artifact.

@selfissued selfissued left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

@peppelinux

Copy link
Copy Markdown
Member Author

@fmarino-ipzs ^

@RalphBragg

Copy link
Copy Markdown
Collaborator

Fantastic!

@RalphBragg RalphBragg left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM - thanks for this.

@fmarino-ipzs fmarino-ipzs left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks @peppelinux , the direction makes sense to me. I left just some comments below, mostly doubts or clarification requests. It's possible I misread some parts, so please correct me.

Comment thread openid-federation-wallet-1_0.md Outdated
Comment thread openid-federation-wallet-1_0.md Outdated
Comment thread openid-federation-wallet-1_0.md Outdated
Comment thread openid-federation-wallet-1_0.md
Comment thread openid-federation-wallet-1_0.md Outdated
Comment thread openid-federation-wallet-1_0.md Outdated
Comment thread openid-federation-wallet-1_0.md Outdated
Comment thread openid-federation-wallet-1_0.md Outdated
Comment thread openid-federation-wallet-1_0.md Outdated
Comment thread openid-federation-wallet-1_0.md Outdated
Co-authored-by: fmarino-ipzs <77629526+fmarino-ipzs@users.noreply.github.com>
Comment thread openid-federation-wallet-1_0.md Outdated
Co-authored-by: fmarino-ipzs <77629526+fmarino-ipzs@users.noreply.github.com>
Co-authored-by: Giuseppe De Marco <demarcog83@gmail.com>
@peppelinux
peppelinux deployed to github-pages October 2, 2026 10:53 — with GitHub Actions Active
@peppelinux
peppelinux deployed to github-pages October 2, 2026 11:25 — with GitHub Actions Active

This branch was successfully deployed

1 active deployment
github-pages — 508fa323 Deployed Oct 2, 2026 by peppelinux via build-and-deploy #155
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Credential Verifier instances (POS terminals, mobile readers) have no trust model: define the Wallet Provider pattern for the verifier side

5 participants