WS_AP_MS_ProtocolMessages_037a¶
Objective¶
Verify that the Wallet sends a syntactically correct body of the Wallet Instance Attestation as Client Attestation, when using Pushed Authorization Requests for issuance.
References¶
- [CIR 2024/2979 amended] annex Ib
- [ETSI TS 119 472-3] section 4.4
- [HAIP] section 4.3
- [OpenID4VCI] section E
- [IETF draft-attestation-based-client-auth] section 5.1
Profile applicability¶
None
EUDI-wallet relevancy¶
EUDI_specific | EUDI_required
Technology¶
Issuance via Redirects.
Preconditions¶
- Wallet is set to 'default_configuration_1'
- End-user is engaging with a Credential Issuer using a User-agent.
- Wallet started engagement with Credential Issuer.
- Wallet successfully obtained Credential Issuer Metadata.
- Wallet send a HTTP POST Request for a Pushed Authorization Request to the PAR Endpoint of the selected Authorization Server.
- Wallet send a correctly signed and trusted Wallet Instance Attestation as a Client Attestation.
Test Scenario¶
- Verify the contents of the Wallet Instance Attestation (i.e. the JWT body).
Expected results¶
- The WIA contains the following top-level claims:
wallet_namewallet_versionwallet_solution_certification_informationclient_statusexpwallet_linkisssubcnf- (optionally)
iat - (optionally)
nbf