Skip to content

Commit 8dc4f7e

Browse files
authored
Merge pull request #266 from oauth-wg/265-key-resolution-recommendations
clarification on recommendations for key resolution
2 parents 4b51b51 + c87da71 commit 8dc4f7e

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

draft-ietf-oauth-status-list.md

+1-1
Original file line numberDiff line numberDiff line change
@@ -895,7 +895,7 @@ A Status List Token in the CWT format should follow the security considerations
895895

896896
## Key Resolution and Trust Management {#key-management}
897897

898-
This specification does not mandate specific methods for key resolution and trust management, however the following recommendations are made:
898+
This specification does not mandate specific methods for key resolution and trust management, however the following recommendations are made for specifications, profiles, or ecosystems that are planning ot make use of the Status List mechanism:
899899

900900
If the Issuer of the Referenced Token is the same entity as the Status Issuer, then the same key that is embedded into the Referenced Token may be used for the Status List Token. In this case the Status List Token may use:
901901
- the same `x5c` value or an `x5t`, `x5t#S256` or `kid` parameter referencing to the same key as used in the Referenced Token for JOSE.

0 commit comments

Comments
 (0)