You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
rulebooks/rb-base/verifier-base-verification.md is still v0.1 "Initial draft" (06.05.2026) and carries unresolved inline remarks (e.g. terminology at 4.2.2 — "is 'authentication' the right term?", and "[Do we need this?]" around 4.2.1). It defines the 8 verification steps:
Steps 4.2.2–4.2.4 are specified as TLOL-based for QEAAs. But IBAN-OV is an EAA — and the rulebook itself states (l. 38) that an EAA "is and can not be included in the TLOL". The ADR referenced at l. 66 ("EAA provider identity verification based on chaining and TLOL") is the open design point here (tracked in #48).
The MVP reading we plan to implement
Given the PA3 MVP sets mutual authentication to true, we plan to:
Context
rulebooks/rb-base/verifier-base-verification.mdis still v0.1 "Initial draft" (06.05.2026) and carries unresolved inline remarks (e.g. terminology at 4.2.2 — "is 'authentication' the right term?", and "[Do we need this?]" around 4.2.1). It defines the 8 verification steps:Steps 4.2.2–4.2.4 are specified as TLOL-based for QEAAs. But IBAN-OV is an EAA — and the rulebook itself states (l. 38) that an EAA "is and can not be included in the TLOL". The ADR referenced at l. 66 ("EAA provider identity verification based on chaining and TLOL") is the open design point here (tracked in #48).
The MVP reading we plan to implement
Given the PA3 MVP sets mutual authentication to true, we plan to:
Is that the expected MVP reading for conformance purposes?