|
1376 | 1376 | that the Entity at the beginning of the Trust Chain |
1377 | 1377 | has in common with the audience of the JWT. |
1378 | 1378 | Otherwise, the issuer is free to select the Trust Anchor to use. |
| 1379 | + </t> |
| 1380 | + <t> |
1379 | 1381 | Most signed JWTs MAY include the |
1380 | 1382 | <spanx style="verb">trust_chain</spanx> JWS header parameter, |
1381 | 1383 | with a few exceptions. |
|
1423 | 1425 | Inclusion of both Trust Chains enables achieving |
1424 | 1426 | the Federation Integrity and Metadata Integrity properties, |
1425 | 1427 | as defined in <xref target="App-Fed-Linkage"/>. |
| 1428 | + </t> |
| 1429 | + <t> |
1426 | 1430 | Entity Configurations and Subordinate Statements MUST NOT |
1427 | 1431 | contain the <spanx style="verb">peer_trust_chain</spanx> header parameter, |
1428 | 1432 | as they are integral components of a Trust Chain. |
@@ -7528,7 +7532,7 @@ HTTP/1.1 302 Found |
7528 | 7532 | </t> |
7529 | 7533 | </section> |
7530 | 7534 |
|
7531 | | - <section title="Rationale for the Trust Chain in the Request" anchor="TrustChainParamRationale"> |
| 7535 | + <section title="Rationale for Trust Chains in the Request" anchor="TrustChainRationale"> |
7532 | 7536 | <t> |
7533 | 7537 | Both Automatic and Explicit Client Registration support |
7534 | 7538 | the submission of the Trust Chain embedded in the Request, |
@@ -7567,6 +7571,15 @@ HTTP/1.1 302 Found |
7567 | 7571 |
|
7568 | 7572 | </list> |
7569 | 7573 | </t> |
| 7574 | + <t> |
| 7575 | + Both also support the submission of the Peer Trust Chain, |
| 7576 | + which provides a Trust Chain between the OP |
| 7577 | + and the Trust Anchor the RP selected. |
| 7578 | + As described in <xref target="peer_trust_chain_head_param"/>, |
| 7579 | + inclusion of both Trust Chains enables achieving |
| 7580 | + the Federation Integrity and Metadata Integrity properties, |
| 7581 | + as defined in <xref target="App-Fed-Linkage"/>. |
| 7582 | + </t> |
7570 | 7583 | </section> |
7571 | 7584 |
|
7572 | 7585 | </section> |
|
0 commit comments