- From: Michael Herman (Trusted Digital Web) <mwherman@parallelspace.net>
- Date: Mon, 23 Aug 2021 16:30:53 +0000
- To: Leonard Rosenthol <lrosenth@adobe.com>, Henry Story <henry.story@gmail.com>
- CC: "public-credentials (public-credentials@w3.org)" <public-credentials@w3.org>
- Message-ID: <MWHPR1301MB209458BFBB042DBD285D4181C3C49@MWHPR1301MB2094.namprd13.prod.outlook.>
Thank you Leonard. At the risk real of being repetitive… What I'm looking for is a specification (or group of specifications) that we can model/pattern/structure the "VC Specification" after ...i.e. in a similar way. Currently, for example, we have the "data model specification", the "use cases" document, an "implementation guide" but, for example, we don't have a top-level document that knits them together (don’t jump on this idea just yet 😊). So with the above motivation, what, in your mind, is a "best in class" specification (or group of specifications) that describe something similar to "a Verifiable Credentials platform as a set of data models and protocols for creating and verifying verifiable data packets and their exchange between 2 or more software agents (don't get hung up on the specific wording)"? Michael From: Leonard Rosenthol <lrosenth@adobe.com> Sent: August 23, 2021 8:44 AM To: Michael Herman (Trusted Digital Web) <mwherman@parallelspace.net>; Henry Story <henry.story@gmail.com> Cc: public-credentials (public-credentials@w3.org) <public-credentials@w3.org> Subject: Re: What are VCs similar to? Michael – there is no question that you can add properties to an X.509 cert…as you say, folks have been doing it for quite some time. What I called out, which is a key part of a VC (and the protected headers of a *AdES package), is that those properties are tamper-evidently secured. Leonard From: Michael Herman (Trusted Digital Web) <mwherman@parallelspace.net<mailto:mwherman@parallelspace.net>> Date: Monday, August 23, 2021 at 10:02 AM To: Leonard Rosenthol <lrosenth@adobe.com<mailto:lrosenth@adobe.com>>, Henry Story <henry.story@gmail.com<mailto:henry.story@gmail.com>> Cc: public-credentials (public-credentials@w3.org<mailto:public-credentials@w3.org>) <public-credentials@w3.org<mailto:public-credentials@w3.org>> Subject: RE: What are VCs similar to? RE: you can’t attach other data in a tamper-evident way, to a cert. I believe you actually can (but may be wrong at the edges). Back in 2002, as a founding Groove Networks business partner, I built a software licensing key solution called Parallelspace Softpass that uses custom properties in X.509 certificates to encode the software license for a specific application, specific edition of the apps, specific up-sell options, etc. to run on specific computers. We used the Certificate Authority service on a Windows Server 2000 box. We used the default Windows CA web GUI to initiate the creation of each cert and then used some sort of Windows CA command line tool to add our custom properties. Then went back into the Windows CA web GUI to issue and download the physical X.509 certificate (as well as our own root certificate) and we would email these as plain old attachments to our customers. For historical interest, attached is a copy of the Parallelspace SoftPass programmers' guide. But even cooler, it appears that in 2002 I had a sense for what a “decentralized software solutions business ecosystem” might be comprised of (from page 6)… [cid:image001.jpg@01D79809.A04CBBF0] I guess I’ve been working on decentralized software solutions for 19 years. 😉 😊 Best regards, Michael Herman Far Left Self-Sovereignist Self-Sovereign Blockchain Architect Trusted Digital Web Hyperonomy Digital Identity Lab Parallelspace Corporation [cid:image004.jpg@01D79809.F073AF80] From: Leonard Rosenthol <lrosenth@adobe.com<mailto:lrosenth@adobe.com>> Sent: August 23, 2021 7:28 AM To: Henry Story <henry.story@gmail.com<mailto:henry.story@gmail.com>>; Michael Herman (Trusted Digital Web) <mwherman@parallelspace.net<mailto:mwherman@parallelspace.net>> Cc: public-credentials (public-credentials@w3.org<mailto:public-credentials@w3.org>) <public-credentials@w3.org<mailto:public-credentials@w3.org>> Subject: Re: What are VCs similar to? I would argue that a VC is *NOTHING* like an X.509 cert…. It is, instead, some piece of data *signed by* an X.509 cert. Consider that you can’t sign things with a VC and you can’t attach other data in a tamper-evident way, to a cert. If anything, a VC is more like a CAdES or XAdES-encoded blob of data. Leonard From: Henry Story <henry.story@gmail.com<mailto:henry.story@gmail.com>> Date: Monday, August 23, 2021 at 7:03 AM To: Michael Herman (Trusted Digital Web) <mwherman@parallelspace.net<mailto:mwherman@parallelspace.net>> Cc: public-credentials (public-credentials@w3.org<mailto:public-credentials@w3.org>) <public-credentials@w3.org<mailto:public-credentials@w3.org>> Subject: Re: What are VCs similar to? > On 23. Aug 2021, at 11:49, Michael Herman (Trusted Digital Web) <mwherman@parallelspace.net<mailto:mwherman@parallelspace.net>> wrote: > > If you assume a simple definition of a Verifiable Credentials platform as a set of data models and protocols for creating and verifying verifiable data packets and their exchange between 2 or more software agents (don't get hung up on the specific wording), what existing protocols/platform standards, in your mind, are the most similar to VCs (at a top-level)? > - DNS? > - TCP packets? > - SOAP messages? > - something else? X509 Certificates (with 40 years of tech improvements added to them). A Verifiable Claim is just a signed content, and the big leap of VC stack is that it is built on well defined, open, extensible logics. Henry > > Michael Herman > > Get Outlook for Android
Attachments
- image/jpeg attachment: image001.jpg
   
- image/jpeg attachment: image004.jpg
   
Received on Monday, 23 August 2021 16:31:14 UTC