Relying Parties cannot trust Verifiers in an enterprise: that role is reserved for Identity Providers. Therefore, it is important to separate the trust anchors between the two, and make that a governance requirement. This has to be addressed likely by the GRC SIG though it has implications on TWI SIG and all Consortium projects that authenticate attested workloads.
Relying Parties cannot trust Verifiers in an enterprise: that role is reserved for Identity Providers. Therefore, it is important to separate the trust anchors between the two, and make that a governance requirement. This has to be addressed likely by the GRC SIG though it has implications on TWI SIG and all Consortium projects that authenticate attested workloads.