https://openid.net/specs/openid4vc-high-assurance-interoperability-profile-1_0.html#section-4.4.1 doesn't contain these two items:
- The X.509 certificate of the trust anchor MUST NOT be included in the x5c JOSE header of the key attestation.
- The X.509 certificate signing the key attestation MUST NOT be self-signed.
which I think we include everywhere else we mention the x5c Jose header. I think we probably intended these to be the case in this case too.
https://openid.net/specs/openid4vc-high-assurance-interoperability-profile-1_0.html#section-4.4.1 doesn't contain these two items:
which I think we include everywhere else we mention the x5c Jose header. I think we probably intended these to be the case in this case too.