Skip to content

Commit 248f679

Browse files
committed
Update trust_anchor validation rules
1 parent 2b7af26 commit 248f679

File tree

1 file changed

+8
-5
lines changed

1 file changed

+8
-5
lines changed

openid-federation-1_0.xml

Lines changed: 8 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -930,11 +930,14 @@
930930
</t>
931931
<t>
932932
If the <spanx style="verb">trust_anchor</spanx> Claim is present,
933-
validate that its value is an Entity Identifier.
934-
Implementations MAY retrieve the Entity Configuration for the
935-
Entity Identifier and validate that it is a Trust Anchor,
936-
and they MAY also validate that it is the Trust Anchor
937-
used for the Explicit Registration.
933+
validate that its value is a URL
934+
using the <spanx style="verb">https</spanx> scheme.
935+
Implementations MAY validate that the Entity Identifier matches
936+
one of the Trust Anchors configured for the deployment.
937+
Furthermore, implementations MAY validate that the
938+
Entity Configuration for the Entity Identifier contains
939+
information compatible with the configured Trust Anchor information
940+
- especially the keys.
938941
This Claim MUST NOT be present in Entity Statements that are not
939942
Explicit Registration responses.
940943
</t>

0 commit comments

Comments
 (0)