You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Mention in section 12.2.2.1. that OP needs to verify the "aud" claim in the received Entity Statements - that the claim is present and it has a single value that is the OP's Entity Identifier.
This check is required to prevent the misuse of an RP's EC published at its well-known endpoint. In a federation that supports both methods of client registration - automatic and explicit, if the "aud" check isn't made by the OP, one could download the RP's EC and use it to trigger its registration at the OP.
The text was updated successfully, but these errors were encountered:
Mention in section 12.2.2.1. that OP needs to verify the "aud" claim in the received Entity Statements - that the claim is present and it has a single value that is the OP's Entity Identifier.
This check is required to prevent the misuse of an RP's EC published at its well-known endpoint. In a federation that supports both methods of client registration - automatic and explicit, if the "aud" check isn't made by the OP, one could download the RP's EC and use it to trigger its registration at the OP.
The text was updated successfully, but these errors were encountered: