Skip to content

Commit dbbc602

Browse files
committed
Add rationale for Peer Trust Chain in the request
1 parent 143061e commit dbbc602

File tree

1 file changed

+14
-1
lines changed

1 file changed

+14
-1
lines changed

openid-federation-1_0.xml

Lines changed: 14 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1376,6 +1376,8 @@
13761376
that the Entity at the beginning of the Trust Chain
13771377
has in common with the audience of the JWT.
13781378
Otherwise, the issuer is free to select the Trust Anchor to use.
1379+
</t>
1380+
<t>
13791381
Most signed JWTs MAY include the
13801382
<spanx style="verb">trust_chain</spanx> JWS header parameter,
13811383
with a few exceptions.
@@ -1423,6 +1425,8 @@
14231425
Inclusion of both Trust Chains enables achieving
14241426
the Federation Integrity and Metadata Integrity properties,
14251427
as defined in <xref target="App-Fed-Linkage"/>.
1428+
</t>
1429+
<t>
14261430
Entity Configurations and Subordinate Statements MUST NOT
14271431
contain the <spanx style="verb">peer_trust_chain</spanx> header parameter,
14281432
as they are integral components of a Trust Chain.
@@ -7528,7 +7532,7 @@ HTTP/1.1 302 Found
75287532
</t>
75297533
</section>
75307534

7531-
<section title="Rationale for the Trust Chain in the Request" anchor="TrustChainParamRationale">
7535+
<section title="Rationale for Trust Chains in the Request" anchor="TrustChainRationale">
75327536
<t>
75337537
Both Automatic and Explicit Client Registration support
75347538
the submission of the Trust Chain embedded in the Request,
@@ -7567,6 +7571,15 @@ HTTP/1.1 302 Found
75677571

75687572
</list>
75697573
</t>
7574+
<t>
7575+
Both also support the submission of the Peer Trust Chain,
7576+
which provides a Trust Chain between the OP
7577+
and the Trust Anchor the RP selected.
7578+
As described in <xref target="peer_trust_chain_head_param"/>,
7579+
inclusion of both Trust Chains enables achieving
7580+
the Federation Integrity and Metadata Integrity properties,
7581+
as defined in <xref target="App-Fed-Linkage"/>.
7582+
</t>
75707583
</section>
75717584

75727585
</section>

0 commit comments

Comments
 (0)