WS_AP_SM_DeviceBinding_002b¶
Objective¶
Verify that the Wallet Provider correctly signs the Client Attestation used by the Wallet to authenticate at the PAR Endpoint of the Authorization Server, when using Pushed Authentication Requests in the Authorization Code Flow for issuance.
References¶
- [CIR 2024/2979 amended] annex Ib
- [ETSI TS 119 472-3] section 4.4
- [HAIP] section 4.3, 4.4.1
- [OpenID4VCI] section 5.1.4, E
- [IETF draft-attestation-based-client-auth] section 5.1
- [ECCG ACM] section 5.2
Profile applicability¶
None
EUDI-wallet relevancy¶
EUDI_generic | EUDI_required
Technology¶
Credential Issuance using the Authorization Code Flow.
Preconditions¶
- Wallet is set to 'default_configuration_1'
- Wallet started engagement with Credential Issuer.
- Wallet successfully obtained Credential Issuer Metadata.
- Wallet send an HTTP POST Request for a Pushed Authorization Request to the PAR Endpoint of the selected Authorization Server.
- The HTTP Request to the PAR Endpoint of the Authorization Server contains a syntactically correct
OAuth-Client-AttestationHTTP header. - The Client Attestation used by the Wallet to authenticate to the PAR Endpoint is a correctly serialized signed JWT.
- The Client Attestation uses an acceptable signature algorithm.
Test Scenario¶
- Verify the signature of the Client Attestation, using the public key identified using the
x5cJOSE header.
Expected results¶
- The signature is valid.