You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
JARM spec says 'If unspecified, the default algorithm to use for signing authorization responses is RS256. The algorithm none is not allowed.' and I don't see that override in openid4vp (so if you don't specify it then it's RS256). but openid4vp spec makesauthorization_signed_response_alg optional because signing in JARM in openid4vp is optional. need to make clear that in openid4vp, ifauthorization_signed_response_alg` is ommitted, there is no default value, default is not signign
The text was updated successfully, but these errors were encountered:
JARM spec says 'If unspecified, the default algorithm to use for signing authorization responses is RS256. The algorithm none is not allowed.' and I don't see that override in openid4vp (so if you don't specify it then it's RS256).
but openid4vp spec makes
authorization_signed_response_algoptional because signing in JARM in openid4vp is optional. need to make clear that in openid4vp, if
authorization_signed_response_alg` is ommitted, there is no default value, default is not signignThe text was updated successfully, but these errors were encountered: