CD-004 - Generic Verifier - Security Enforcement, AES256 Migration & Status List Gap Closure
Security Enforcement, AES256 Migration & Status List Gap Closure
Status: Released
Published: 22.07.2026
Effective: 17.08.2026
Affected Components: Generic Verifier, swiyu Wallet
Internal Reference: EIDARTFE-1531, EIDARTFE-1564, EIDARTFE-1717, EIDARTFE-1726
This dossier bundles three related Verifier-side changes into a single migration wave.
- It closes the remaining security-enforcement gaps in OpenID for Verifiable Presentations (OID4VP) by enforcing encrypted Authorization Responses (direct_post.jwt), DCQL-only presentation queries, and Signed Presentation Requests, all of which are already implemented but currently only optionally supported under the EMC (Expand-Migrate-Contract) pattern.
- It migrates encryption from AES128-GCM to AES256-GCM; following EMC, all components first accept both algorithms, with the Wallet required to support this ahead of the Issuer and Verifier.
- It closes the remaining Status List gaps required for the swiyu 1.0 go-live, including status-verification configurability and caching. During the transition period, non-enforcing behavior continues to be accepted where noted; afterwards, non-compliant Verifiers can no longer participate in the ecosystem.
Action required
⚠️ Required soon 🚨 Breaking 🆕 Optional ✅ Improvement 🐞 Fix
Generic Verifier
Version 4.0.x
- See: Release notes
Migration steps
- Migrate to generic Verifier 4.0.x. See migrations guides
- Contract phase: Payload Encryption and signed meta data become mandatory at the swiyu Wallet; non-conforming Verifier can no longer verify credentials from a swiyu Wallet.
Timeline
17.08.2026 Wallet-side 1.17.x security enforced (payload encryption) requires the generic Verifier 4.0.x.