Skip to main content

Topic

Digital Identity and Credentials

Within the Topic facet, Digital Identity and Credentials topic intelligence connects articles that share a specific subject, signal focus, or monitoring theme. The page gives readers a richer path through related reporting, source evidence, market actors, and infrastructure implications, with enough context to understand why the topic matters across company movements, governance decisions, regional exposure, and operational risk. Readers can compare recurring signals, affected organisations, public evidence, market context, service continuity, procurement, competition, compliance, and strategic planning questions behind the subject instead of stopping at a thin list of matching articles. It explains what the topic covers, which infrastructure actors or policies are involved, what evidence supports the coverage, and why the subject may matter for operators, customers, investors, and policy readers.

A constrained sensor has already sent a blue identity token through a verified gateway while a three-bound copper authorization voucher travels back from the remote authority above a separate retention, quarantine and identity-transition tray.

IETF

An Enrollment Voucher Arrives After Identity Leaves the Device

A constrained device can withhold its operational identity and still disclose enough to be enrolled. In Lightweight Authorization using EDHOC, that disclosure is deliberate: an authenticated domain authenticator receives the device’s enrollment identity and sends it to a trusted…

Sep 8, 2026
AI editorial portrait of Nat Sakimura beside an intact JWS signature lattice, a mismatched critical-extension aperture and a separate unlit application plane

IETF

Nat Sakimura and the Critical Header a Valid Signature Could Not Ignore

A JSON Web Signature can pass its mathematical check and still be unusable. RFC 7515 made room for that outcome through `crit`: an integrity-protected list that tells a verifier which extensions it must understand before it may accept the message. The distinction is easy to miss…

Sep 8, 2026
AI editorial portrait of Justin Richer beside separate token-state, authorization-decision and application-result planes

IETF

Justin Richer and the Active Token That Could Not Approve the Request

An OAuth resource server asks about a bearer token and receives the most reassuring two-word answer in the exchange: `active: true`. The token is current, the authorization server recognizes it and the request can move forward. Yet one decision is still missing. The introspection…

Sep 8, 2026
AI editorial portrait of Rifaat Shekh-Yusef beside a nonce-scoped request sequence separated from a durable application ledger

IETF

Rifaat Shekh-Yusef and the Nonce Count That Could Not Number the Transaction

The first authenticated request carries `nc=00000001`. It looks uncannily like the beginning of a transaction ledger: neat, monotonic and attached to a credential check. But in the HTTP Digest scheme edited by Rifaat Shekh-Yusef, that small hexadecimal field has a narrower…

Sep 8, 2026
AI editorial portrait of Peter Saint-Andre between an anchored client identity and a separate certificate comparison plane

IETF

Peter Saint-Andre and the Certificate Match That Could Not Choose the Service

The certificate was valid for the name the client checked. That sentence sounds like the end of authentication, but it hides the first and more consequential choice: why did the client check that name? Peter Saint-Andre and Rich Salz make the order explicit in RFC 9525. The…

Sep 7, 2026
AI editorial portrait of Alexey Melnikov beside a completed identity exchange branching through separate application authorization gates

IETF

Alexey Melnikov and the Authentication Success That Could Not Grant a Service

The status light turned green. The credentials had been accepted, an identity had been associated with the session, and the exchange was over. Yet the next operation could still be refused without contradiction. The architecture Alexey Melnikov and Kurt Zeilenga set out in RFC…

Sep 7, 2026
One pale canopy spans three different certificate workstations fitted with matching navy stencils, while an incompatible brass stencil rests unused beside them.

IETF

One CA Name, Several Ways to Issue

A buyer reviewing certificate operations asks a simple question: if DNS authorizes one certification-authority name with an account and a validation method, does that restriction govern every issuing system behind the name? RFC 8657 makes the answer consequential. A shared CA…

Sep 7, 2026
A cyan identity signal enters a glass session chamber before an amber authority gate guarding registry objects; an old brass cookie stops at a cutover line while a separate API-key rail continues.

Story

RIPE Database Is Switching to OIDC. Maintainer Authority Does Not Move With the Session

RIPE NCC plans to replace a site-wide cookie with an OIDC session for interactive RIPE Database use. That can improve authentication, but the harder acceptance question begins after login: which `mntner` authorises this identity to change this entity, under which session regime…

Sep 7, 2026
Daniel Fett in an AI editorial portrait beside an abstract issuer comparison gate that separates a matching endpoint route from a stopped mismatch route.

Leaders

Daniel Fett and the Issuer Field That Named the Server, Not the Token

An OAuth callback can contain the right state and a real authorization code and still be on its way to the wrong server. RFC 9207 adds one small comparison before that mistake becomes a disclosure: did the server named in the response match the issuer the client recorded when the…

Sep 7, 2026
Anonymous learners in an African training space as lesson events cross a signup threshold and flow into a transparent audit ledger.

Story

AFRINIC Reports 3,927,253 Learning Behaviours. Its Academy Signup Does Not Explain the Record

AFRINIC has published an unusually precise measure of its online teaching: 3,927,253 learning behaviours tracked after xAPI was integrated into every lesson. Precision makes the Academy look measurable. It also makes the missing join between the public measurement claim and the…

Sep 6, 2026
A sealed layered credential holds many opaque compartments while two selected translucent disclosure cards travel through matching paths to a verifier, with a separate holder-controlled key token below.

IETF

Reveal Less, Prove Enough: RFC 9901 and the Control Surface of Selective Disclosure

One issuer-signed credential can disclose an address to one verifier and a birthdate to another because its signed JSON carries salted digests while the holder presents only selected cleartext Disclosures. That mechanism is defined by RFC 9901, an IETF Standards Track…

Sep 6, 2026