[media-types] [IANA #1421575] application/vp+sd-jwt regi stration request
Michael Jones <[email protected]>
| Newsgroups | gmane.ietf.types |
|---|---|
| Message-ID | <MW2PR12MB2508DFFA21133C6DD9137CA9B7D9A@MW2PR12MB2508.namprd12.prod.outlook.com> |
The IETF made a liaison inquiry to the W3C about whether the security considerations for the "Securing Verifiable Credentials using JOSE and COSE" specification are complete and accurate. The official response from the W3C below saying that they are complete and accurate went to the designated experts on November 6th. The inquiry and response are included below.
Alexey, Darrel, and Muray - can you please now approve this registration on this basis?
Thank you,
-- Mike
From: Ivan Herman <[email protected]>
Sent: Thursday, November 6, 2025 6:38 AM
To: Liaison Statement Management Tool <[email protected]>
Cc: Brent Zundel <[email protected]>; Philippe le Hégaret <[email protected]>; Simone Onofri <[email protected]>; Alexey Melnikov <[email protected]>; Andy Newton <[email protected]>; Darrel Miller <[email protected]>; Martin Thomson <[email protected]>; Orie Steele <[email protected]>; [email protected]; [email protected]; [email protected]; W3C Chairs of VC WG <[email protected]>; Mike Jones <[email protected]>
Subject: Re: New Liaison Statement, "application/vp+sd-jwt media type registration request from W3C"
Dear Martin, and experts in general,
The "Securing Verifiable Credentials using JOSE and COSE" specification[1] that contains the respective media type specifications, as well as the core document that the JOSE/COSE format relies on, i.e., the "Verifiable Credentials Data Model v2.0" specification[2], have both been thoroughly reviewed by W3C's security and privacy groups before publication (as mandated by the W3C process). The relevant security and privacy considerations have been published as part of the respective specifications (see [3] and [4] for JOSE/COSE, an [5] and [6] for VC).
Based on that, we can claim that the security and privacy considerations, referenced in the specifications, are true and complete, and that all known concerns have indeed been properly documented or addressed.
I hope this covers your concerns
Sincerely
Ivan Herman
W3C staff contact for the Verifiable Credentials Working Group
[1] https://www.w3.org/TR/vc-jose-cose/
[2] https://www.w3.org/TR/vc-data-model-2.0/
[3] https://www.w3.org/TR/vc-jose-cose/#security-considerations
[4] https://www.w3.org/TR/vc-jose-cose/#privacy-considerations
[5] https://www.w3.org/TR/vc-data-model-2.0/#security-considerations
[6] https://www.w3.org/TR/vc-data-model-2.0/#privacy-considerations
On 4 Nov 2025, at 22:00, Liaison Statement Management Tool <[email protected]<mailto:[email protected]>> wrote:
Title: application/vp+sd-jwt media type registration request from W3C
Submission Date: 2025-11-04
URL of the IETF Web page: https://datatracker.ietf.org/liaison/2073/
To: W3C
From: Applications and Real-Time Area (art)
Purpose: For information
Email Addresses
---------------
From: Martin Thomson <[email protected]<mailto:[email protected]>>
To: [email protected]<mailto:[email protected]>, [email protected]<mailto:[email protected]>, [email protected]<mailto:[email protected]>, [email protected]<mailto:[email protected]>
Cc: Martin Thomson <[email protected]<mailto:[email protected]>>,Alexey Melnikov <[email protected]<mailto:[email protected]>>,Darrel Miller <[email protected]<mailto:[email protected]>>,[email protected],[email protected]
Response Contacts: Orie Steele <[email protected]<mailto:[email protected]>>,Andy Newton <[email protected]<mailto:[email protected]>>
Technical Contacts: Murray Kucherawy <[email protected]<mailto:[email protected]>>,
Body: Earlier in 2025, IANA forwarded to the appointed Designated Experts (DEs) an application by the W3C to register the media type application/vp+sd-jwt. DEs are appointed to their positions by the Internet Engineering Steering Group.
Media type DEs are tasked primarily with ensuring that registrations, especially of those on the standards tree, are properly documented and that the registration template is properly completed. With respect to security in particular, the DEs are expected to ensure that a reasonably thorough security review was done and the results of this are associated with the registration. Note, however, that the DEs are not necessarily security experts and therefore are not expected to affirm or extend any security review that was done, but merely to assure that appropriate due diligence was executed. Moreover, as per RFC 6838, there is no obligation that a media type be devoid of security risks, only that all known risks are properly documented.
Media type requests that are under review are revealed to the IETF community via the [email protected]<mailto:[email protected]> mailing list. On that basis, we received feedback that deployment of this media type would be harmful to the Internet and urged careful consideration and review. When clarifying the objection, it was found that this is not a singular position, and that these concerns were raised during development of the work by the W3C.
Before continuing with the approval process, the DEs request that the W3C review the record that was the source of this registration and advise as to whether the Security Considerations (or equivalent) material in the referenced specification is true and complete, and that all known concerns have indeed been properly documented or addressed. We will hold this registration until a reply has been received.
Attachments:
No document has been attached
----
Ivan Herman, W3C
Home: http://www.w3.org/People/Ivan/
mobile: +33 6 52 46 00 43
_______________________________________________
media-types mailing list -- [email protected]
To unsubscribe send an email to [email protected]