Assurance: 6.3. Notified eID system (eIDAS) : Incorrect example
The example seems to be missing the required evidence
element:
https://openid.net/specs/openid-connect-4-identity-assurance-1_0.html#id-document-1
Comments (5)
-
-
reporter Thanks! If that’s so it would make sense to mark
evidence
as OPTIONAL in https://openid.net/specs/openid-connect-4-identity-assurance-1_0.html#rfc.section.4.1(and the other elements which haven’t got the requirement set in that section - time, verification_process)
-
reporter I had missed that the requirements are actually there in the text. Perhaps they could stand out if mentioned next to each parameter: OPTIONAL unless required by the trust framework.
-
The spec is a bit sloppy right now re optionality. I suggest to make a pass through the spec and add REQUIRED/OPTIONAL to any element.
-
- changed status to resolved
fixed by PR #8 - everything but trust_framework, verification, claims & type is optional now
- Log in to comment
evidence is not required. A notified eID system under eIDAS is one example of an IDP that does not need to provide RPs with evidence due to the legal framework (well-defined regulation, EU member state takes liability).