You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The RP MUST ensure that the metadata it was registered with at the OP complies with the Trust Chain openid_relying_party policies, which Trust Chain is resolved using the trust_anchor_id and authority_hints claims of the received registration Entity Statement. The RP SHOULD perform this check by applying the resolved policies to the metadata as specified in Section 6.1.4.1, or utilize another equivalent method.
While the intention of this step is obvious, the second sentence remains vague: What exactly is to be checked here?
Should RP apply the resolved policies to the received metadata and check that this policy application did not change the metadata?
Or something different?
The text was updated successfully, but these errors were encountered:
If we go back a year or more (not sure exactly when the switch happened) the OP was expected to calculate a set of metadata policies that if used on the RP's metadata would result in metadata the OP was happy with.
This was a bit cumbersome so we decided to have the OP just send back the complete metadata it wanted the RP to use.
The RP should still verify that the received metadata complies with metadata policies it can collect from the trust chain that starts with itself and ends in the TA with entity_id = trust_anchor_id.
Step 4 in Section 12.2.2.2 on RP processing of an explicit client registration response says:
While the intention of this step is obvious, the second sentence remains vague: What exactly is to be checked here?
Should RP apply the resolved policies to the received metadata and check that this policy application did not change the metadata?
Or something different?
The text was updated successfully, but these errors were encountered: