WS_AP_SM_DeviceBinding_003a¶
Objective¶
Verify that the Wallet uses an acceptable signature algorithm for signing the Client Attestation Proof of Possession used by the Wallet to authenticate at the PAR Endpoint of the Authorization Server, when using Pushed Authentication Requests in the Authorization Code Flow for issuance.
References¶
- [CIR 2024/2979 amended] annex Ia, Ib
- [ETSI TS 119 472-3] section 4.4
- [HAIP] section 4.3
- [OpenID4VCI] section 5.1.4, E
- [IETF draft-attestation-based-client-auth] section 5.2
- [ECCG ACM] section 5.2
Profile applicability¶
None
EUDI-wallet relevancy¶
EUDI_generic | EUDI_required
Technology¶
Credential Issuance using the Authorization Code Flow.
Preconditions¶
- Wallet is set to 'default_configuration_1'
- Wallet started engagement with Credential Issuer.
- Wallet successfully obtained Credential Issuer Metadata.
- Wallet send an HTTP POST Request for a Pushed Authorization Request to the PAR Endpoint of the selected Authorization Server.
- The HTTP Request to the PAR Endpoint of the Authorization Server contains a syntactically correct
OAuth-Client-Attestation-PoPHTTP header. - The Client Attestation Proof of Possession used to authenticate to the PAR Endpoint is a correctly serialized signed JWT.
Test Scenario¶
- Verify the signature algorithm (
algin protected header) used for signing the Client Attestation Proof of Possession.
Expected results¶
- The signature algorithm in
alg:- is on the list of acceptable algorithms [ECCG ACM], and
- is one of
ES256,ES384, orES512.