Salta al contenuto
0
  • Home
  • Piero Bosio
  • Blog
  • Mondo
  • Fediverso
  • News
  • Categorie
  • Old Web Site
  • Recenti
  • Popolare
  • Tag
  • Utenti
  • Home
  • Piero Bosio
  • Blog
  • Mondo
  • Fediverso
  • News
  • Categorie
  • Old Web Site
  • Recenti
  • Popolare
  • Tag
  • Utenti
Skin
  • Chiaro
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Scuro
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Predefinito (Nessuna skin)
  • Nessuna skin
Collassa

Piero Bosio Social Web Site Personale Logo Fediverso

Social Forum federato con il resto del mondo. Non contano le istanze, contano le persone
  1. Home
  2. Categorie
  3. Technical Discussion
  4. Interesting new DID method: "did:self"

Interesting new DID method: "did:self"

Pianificato Fissato Bloccato Spostato Technical Discussion
activitypubdevfedidev
1 Post 1 Autori 14 Visualizzazioni
  • Da Vecchi a Nuovi
  • Da Nuovi a Vecchi
  • Più Voti
Rispondi
  • Risposta alla discussione
Effettua l'accesso per rispondere
Questa discussione è stata eliminata. Solo gli utenti con diritti di gestione possono vederla.
  • fentiger@zotum.net
    fentiger@zotum.net
    fentiger@zotum.net
    scritto su ultima modifica di
    #1
    One consequence of trying to separate identity hosting from the other components of the system is that it makes the other components harder to bootstrap. If I run just one component of my instance in isolation, how can I authenticate to it in order to configure/manage/test it, if I don't have an identity that I can use?

    The answer might be to use a did:self identifier. The flow would look something like

    • Management CLI tool generates a JWT describing a did:self identifier, and stores the private key locally
    • Admin uses scp or something to copy this JWT to the right place on the server
    • The server now has the ID's public key and so the CLI tool can prove that it "owns" the identifier

    Which seems like a reasonable fix for the classic problem of "how do you create the first user", and also a useful fallback for when the system is too badly borked to be able to look up real identities.

    Another interesting property of did:self is that seems to be possible to add extra metadata, such as a human-readable name, to the ID, by using standard JWT claims - without needing the data to appear in the DID document.

    Of course these identities will only be visible to the server they're copied to, not to the whole network, but that shouldn't be a major problem.

    (Cue the peanut gallery, with their suggestions of "it's easy, just do so-and-so", because everything looks easy when you take it out of context...)

    #ActivityPubDev #FediDev
    1 Risposta Ultima Risposta
    0

    Ciao! Sembra che tu sia interessato a questa conversazione, ma non hai ancora un account.

    Stanco di dover scorrere gli stessi post a ogni visita? Quando registri un account, tornerai sempre esattamente dove eri rimasto e potrai scegliere di essere avvisato delle nuove risposte (tramite email o notifica push). Potrai anche salvare segnalibri e votare i post per mostrare il tuo apprezzamento agli altri membri della comunità.

    Con il tuo contributo, questo post potrebbe essere ancora migliore 💗

    Registrati Accedi
    Rispondi
    • Risposta alla discussione
    Effettua l'accesso per rispondere
    • Da Vecchi a Nuovi
    • Da Nuovi a Vecchi
    • Più Voti


    Feed RSS
    Interesting new DID method: "did:self"
    @pierobosio@soc.bosio.info
    NodeBB Contributors
    • Accedi

    • Accedi o registrati per effettuare la ricerca.
    • Primo post
      Ultimo post