Skip to content

The term Issuer SHOULD NOT be used to refer to an entity acting "for all three roles" #220

Closed
@Denisthemalice

Description

@Denisthemalice

On page 3, the text states:

If not further specified, the term Issuer may refer to an entity acting for all three roles.

This sentence should be removed.

The role of the Issuer and of the Status Issuer should be kept separate in the whole document.
A Status Issuer does not have access to the data that has been provided when the user was enrolled by the Issuer.

As a consequence, the following sentence should be reconsidered:

If the roles of the Issuer and the Status Provider are performed by
two different entities, this may give additional privacy assurances
as the Issuer has no means to identify the Relying Party or its
request.

These "additional privacy assurances" exist as soon as the role of the Issuer and of the Status Issuer are kept separate.

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions