|
53 | 53 | intervaltree 3.1.0 |
54 | 54 | Jinja2 3.1.2 |
55 | 55 | lxml 5.3.1 |
56 | | - platformdirs 4.3.6 |
| 56 | + platformdirs 4.3.7 |
57 | 57 | pycountry 24.6.1 |
58 | 58 | PyYAML 6.0.1 |
59 | 59 | requests 2.31.0 |
@@ -2223,7 +2223,7 @@ <h3 id="name-terminology"> |
2223 | 2223 | <dd style="margin-left: 1.5em" id="section-1.2-3.38"> |
2224 | 2224 | Statement of conformance to a |
2225 | 2225 | well-scoped set of trust and/or interoperability requirements |
2226 | | - as determined by an accreditation authority. |
| 2226 | + as determined by an accreditation authority. |
2227 | 2227 | Each Trust Mark has a Trust Mark identifier.<a href="#section-1.2-3.38" class="pilcrow">¶</a> |
2228 | 2228 | </dd> |
2229 | 2229 | <dd class="break"></dd> |
@@ -3997,9 +3997,9 @@ <h4 id="name-operators"> |
3997 | 3997 | </li> |
3998 | 3998 | <li class="normal" id="section-6.1.3-2.9"> |
3999 | 3999 | <p id="section-6.1.3-2.9.1"> |
4000 | | - Metadata parameters and policies that conform to the JSON |
| 4000 | + Metadata parameters and policies that conform to the JSON |
4001 | 4001 | grammar but do not represent interoperable uses of JSON, |
4002 | | - as per Sections 4 and 8 of <span>[<a href="#RFC8259" class="cite xref">RFC8259</a>]</span>, |
| 4002 | + as per Sections 4 and 8 of <span>[<a href="#RFC8259" class="cite xref">RFC8259</a>]</span>, |
4003 | 4003 | can cause unpredictable behavior.<a href="#section-6.1.3-2.9.1" class="pilcrow">¶</a></p> |
4004 | 4004 | </li> |
4005 | 4005 | </ul> |
@@ -4491,8 +4491,8 @@ <h6 id="name-essential"> |
4491 | 4491 | <p id="section-6.1.3.1.7-9"> |
4492 | 4492 | Order of application: Last<a href="#section-6.1.3.1.7-9" class="pilcrow">¶</a></p> |
4493 | 4493 | <p id="section-6.1.3.1.7-10"> |
4494 | | - Operator value merge: The result of merging the values of two |
4495 | | - <code>essential</code> operators is the logical |
| 4494 | + Operator value merge: The result of merging the values of two |
| 4495 | + <code>essential</code> operators is the logical |
4496 | 4496 | disjunction (<code>OR</code>) of the operator values.<a href="#section-6.1.3.1.7-10" class="pilcrow">¶</a></p> |
4497 | 4497 | </section> |
4498 | 4498 | </div> |
@@ -5268,7 +5268,7 @@ <h2 id="name-trust-marks"> |
5268 | 5268 | <code>typ</code> header parameter to prevent |
5269 | 5269 | cross-JWT confusion, per Section 3.11 of <span>[<a href="#RFC8725" class="cite xref">RFC8725</a>]</span>. |
5270 | 5270 | The <code>typ</code> header parameter value MUST be |
5271 | | - <code>trust-mark+jwt</code> |
| 5271 | + <code>trust-mark+jwt</code> |
5272 | 5272 | unless the trust framework in use defines a more specific |
5273 | 5273 | media type value for the particular kind of Trust Mark. |
5274 | 5274 | Trust Marks without a <code>typ</code> header parameter |
@@ -8832,16 +8832,16 @@ <h4 id="name-processing-explicit-client-r"> |
8832 | 8832 | </li> |
8833 | 8833 | <li id="section-12.2.5-1.5"> |
8834 | 8834 | <p id="section-12.2.5-1.5.1"> |
8835 | | - The RP MUST ensure that the metadata it was registered with |
8836 | | - at the OP complies with the Trust Chain |
8837 | | - <code>openid_relying_party</code> policies, |
8838 | | - which Trust Chain is resolved using the |
8839 | | - <code>trust_anchor</code> and |
8840 | | - <code>authority_hints</code> claims of the |
8841 | | - received registration Entity Statement. The RP SHOULD perform this check |
8842 | | - by applying the resolved policies to the metadata as |
8843 | | - specified in <a href="#metadata_policy_resolution" class="auto internal xref">Section 6.1.4.1</a>, or |
8844 | | - utilize another equivalent method.<a href="#section-12.2.5-1.5.1" class="pilcrow">¶</a></p> |
| 8835 | + The RP MUST first ensure that the information it was registered with |
| 8836 | + at the OP contains the same set of entity_types as the request does. |
| 8837 | + After having collected a Trust Chain using the response claim |
| 8838 | + <code>trust_anchor_id</code> as the |
| 8839 | + <code>entity_id</code> for the Trust Anchor and |
| 8840 | + <code>authority_hints</code> as starting points |
| 8841 | + for the Trust Chain collection, |
| 8842 | + the RP SHOULD verify that the response metadata for each entity type is valid |
| 8843 | + by applying the resolved policies to the received metadata, as |
| 8844 | + specified in <a href="#metadata_policy_resolution" class="auto internal xref">Section 6.1.4.1</a>.<a href="#section-12.2.5-1.5.1" class="pilcrow">¶</a></p> |
8845 | 8845 | </li> |
8846 | 8846 | <li id="section-12.2.5-1.6"> |
8847 | 8847 | <p id="section-12.2.5-1.6.1"> |
@@ -12627,7 +12627,7 @@ <h2 id="name-document-history"> |
12627 | 12627 | </li> |
12628 | 12628 | <li class="normal" id="appendix-C-5.13"> |
12629 | 12629 | <p id="appendix-C-5.13.1"> |
12630 | | - Fixed #162: Trust Mark claim <code>id</code> |
| 12630 | + Fixed #162: Trust Mark claim <code>id</code> |
12631 | 12631 | renamed to <code>trust_mark_id</code>. |
12632 | 12632 | Other more specific Trust Mark JWT <code>typ</code> header parameter values |
12633 | 12633 | can be used if defined by trust frameworks in use and understood by the implementation.<a href="#appendix-C-5.13.1" class="pilcrow">¶</a></p> |
|
0 commit comments