Re: Expiry time in Data Model

On Fri, May 20, 2016 at 1:42 PM, David Chadwick <d.w.chadwick@kent.ac.uk>
wrote:

> This is a separate issue. A claim may not have expired, but it may have
> been revoked. Therefore going back to the issuer is a something the
> recipient/relying party will have to decide to do based on its risk
> threshold.
>
> A second parameter of a credential should be whether it is revocable or
> not.
>
> regards
>
> David
>

​The issuer should have a voice in how frequently a claim should be
reverified and how long it can be cached w/out validation - it's not the
exclusive domain of the recipient.​

what is an example of a credential that's irrevocable?

-stone



=====
Matt Stone
501-291-1599

Received on Friday, 20 May 2016 20:00:47 UTC