Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Explicit client registration: Mention that the OP must check the "aud" of the received EC #88

Open
vdzhuvinov opened this issue Sep 12, 2024 · 0 comments · May be fixed by #91
Open

Explicit client registration: Mention that the OP must check the "aud" of the received EC #88

vdzhuvinov opened this issue Sep 12, 2024 · 0 comments · May be fixed by #91
Assignees

Comments

@vdzhuvinov
Copy link
Collaborator

Mention in section 12.2.2.1. that OP needs to verify the "aud" claim in the received Entity Statements - that the claim is present and it has a single value that is the OP's Entity Identifier.

This check is required to prevent the misuse of an RP's EC published at its well-known endpoint. In a federation that supports both methods of client registration - automatic and explicit, if the "aud" check isn't made by the OP, one could download the RP's EC and use it to trigger its registration at the OP.

@selfissued selfissued self-assigned this Sep 12, 2024
@selfissued selfissued linked a pull request Sep 16, 2024 that will close this issue
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants