Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

scaling up delegated authorization #3

Open
cyberphone opened this issue Jun 30, 2021 · 0 comments
Open

scaling up delegated authorization #3

cyberphone opened this issue Jun 30, 2021 · 0 comments

Comments

@cyberphone
Copy link
Member

A problem with outsourced/delegated authorization is that it presumes that the customer database is available for the TPP.

If the issuer issues X.509 certificates instead of public keys only, it should be possible for an external verifier to only need

  • CA root
  • Decryption private key(s)

Certificates would contain account numbers.

The impact on the FWP client would be minimal.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant