Skip to content

Commit c7bd14d

Browse files
committed
Add Security Considerations
1 parent b23787d commit c7bd14d

File tree

2 files changed

+58
-34
lines changed

2 files changed

+58
-34
lines changed

connect/openid-federation-wallet-1_0-05.html

Lines changed: 49 additions & 33 deletions
Original file line numberDiff line numberDiff line change
@@ -1365,35 +1365,38 @@ <h2 id="abstract"><a href="#abstract" class="selfRef">Abstract</a></h2>
13651365
<p id="section-toc.1-1.9.1"><a href="#section-9" class="auto internal xref">9</a>.  <a href="#name-implementation-consideratio" class="internal xref">Implementation Considerations for Offline Flows</a></p>
13661366
</li>
13671367
<li class="compact toc ulBare ulEmpty" id="section-toc.1-1.10">
1368-
<p id="section-toc.1-1.10.1"><a href="#section-10" class="auto internal xref">10</a><a href="#name-iana-considerations" class="internal xref">IANA Considerations</a></p>
1368+
<p id="section-toc.1-1.10.1"><a href="#section-10" class="auto internal xref">10</a><a href="#name-security-considerations" class="internal xref">Security Considerations</a></p>
1369+
</li>
1370+
<li class="compact toc ulBare ulEmpty" id="section-toc.1-1.11">
1371+
<p id="section-toc.1-1.11.1"><a href="#section-11" class="auto internal xref">11</a><a href="#name-iana-considerations" class="internal xref">IANA Considerations</a></p>
13691372
<ul class="compact toc ulBare ulEmpty">
1370-
<li class="compact toc ulBare ulEmpty" id="section-toc.1-1.10.2.1">
1371-
<p id="section-toc.1-1.10.2.1.1"><a href="#section-10.1" class="auto internal xref">10.1</a>.  <a href="#name-oauth-parameters-registry" class="internal xref">OAuth Parameters Registry</a></p>
1373+
<li class="compact toc ulBare ulEmpty" id="section-toc.1-1.11.2.1">
1374+
<p id="section-toc.1-1.11.2.1.1"><a href="#section-11.1" class="auto internal xref">11.1</a>.  <a href="#name-oauth-parameters-registry" class="internal xref">OAuth Parameters Registry</a></p>
13721375
<ul class="compact toc ulBare ulEmpty">
1373-
<li class="compact toc ulBare ulEmpty" id="section-toc.1-1.10.2.1.2.1">
1374-
<p id="section-toc.1-1.10.2.1.2.1.1"><a href="#section-10.1.1" class="auto internal xref">10.1.1</a>.  <a href="#name-dcql_queries" class="internal xref">dcql_queries</a></p>
1376+
<li class="compact toc ulBare ulEmpty" id="section-toc.1-1.11.2.1.2.1">
1377+
<p id="section-toc.1-1.11.2.1.2.1.1"><a href="#section-11.1.1" class="auto internal xref">11.1.1</a>.  <a href="#name-dcql_queries" class="internal xref">dcql_queries</a></p>
13751378
</li>
13761379
</ul>
13771380
</li>
13781381
</ul>
1379-
</li>
1380-
<li class="compact toc ulBare ulEmpty" id="section-toc.1-1.11">
1381-
<p id="section-toc.1-1.11.1"><a href="#section-11" class="auto internal xref">11</a><a href="#name-acknowledgements" class="internal xref">Acknowledgements</a></p>
13821382
</li>
13831383
<li class="compact toc ulBare ulEmpty" id="section-toc.1-1.12">
1384-
<p id="section-toc.1-1.12.1"><a href="#section-12" class="auto internal xref">12</a><a href="#name-normative-references" class="internal xref">Normative References</a></p>
1384+
<p id="section-toc.1-1.12.1"><a href="#section-12" class="auto internal xref">12</a><a href="#name-acknowledgements" class="internal xref">Acknowledgements</a></p>
13851385
</li>
13861386
<li class="compact toc ulBare ulEmpty" id="section-toc.1-1.13">
1387-
<p id="section-toc.1-1.13.1"><a href="#section-13" class="auto internal xref">13</a><a href="#name-informative-references" class="internal xref">Informative References</a></p>
1387+
<p id="section-toc.1-1.13.1"><a href="#section-13" class="auto internal xref">13</a><a href="#name-normative-references" class="internal xref">Normative References</a></p>
13881388
</li>
13891389
<li class="compact toc ulBare ulEmpty" id="section-toc.1-1.14">
1390-
<p id="section-toc.1-1.14.1"><a href="#appendix-A" class="auto internal xref">Appendix A</a> <a href="#name-notices" class="internal xref">Notices</a></p>
1390+
<p id="section-toc.1-1.14.1"><a href="#section-14" class="auto internal xref">14</a><a href="#name-informative-references" class="internal xref">Informative References</a></p>
13911391
</li>
13921392
<li class="compact toc ulBare ulEmpty" id="section-toc.1-1.15">
1393-
<p id="section-toc.1-1.15.1"><a href="#appendix-B" class="auto internal xref">Appendix B</a>.  <a href="#name-document-history" class="internal xref">Document History</a></p>
1393+
<p id="section-toc.1-1.15.1"><a href="#appendix-A" class="auto internal xref">Appendix A</a>.  <a href="#name-notices" class="internal xref">Notices</a></p>
13941394
</li>
13951395
<li class="compact toc ulBare ulEmpty" id="section-toc.1-1.16">
1396-
<p id="section-toc.1-1.16.1"><a href="#appendix-C" class="auto internal xref"></a><a href="#name-authors-addresses" class="internal xref">Authors' Addresses</a></p>
1396+
<p id="section-toc.1-1.16.1"><a href="#appendix-B" class="auto internal xref">Appendix B</a>.  <a href="#name-document-history" class="internal xref">Document History</a></p>
1397+
</li>
1398+
<li class="compact toc ulBare ulEmpty" id="section-toc.1-1.17">
1399+
<p id="section-toc.1-1.17.1"><a href="#appendix-C" class="auto internal xref"></a><a href="#name-authors-addresses" class="internal xref">Authors' Addresses</a></p>
13971400
</li>
13981401
</ul>
13991402
</nav>
@@ -2375,30 +2378,40 @@ <h2 id="name-implementation-consideratio">
23752378
<p id="section-9-5">Using short-lived Trust Chains ensures compatibility with required revocation administrative protocols, such as those defined in a legal framework. For example, if a revocation must be propagated in less than 24 hours, the Trust Chain should not be valid for more than that period.<a href="#section-9-5" class="pilcrow"></a></p>
23762379
</section>
23772380
</div>
2378-
<div id="iana-considerations">
2381+
<div id="security-considerations">
23792382
<section id="section-10">
2383+
<h2 id="name-security-considerations">
2384+
<a href="#section-10" class="section-number selfRef">10. </a><a href="#name-security-considerations" class="section-name selfRef">Security Considerations</a>
2385+
</h2>
2386+
<p id="section-10-1">The security considerations in
2387+
<span>[<a href="#OpenID.Federation" class="cite xref">OpenID.Federation</a>]</span>, <span>[<a href="#OpenID4VP" class="cite xref">OpenID4VP</a>]</span>, and <span>[<a href="#OpenID4VCI" class="cite xref">OpenID4VCI</a>]</span>
2388+
apply to this specification.<a href="#section-10-1" class="pilcrow"></a></p>
2389+
</section>
2390+
</div>
2391+
<div id="iana-considerations">
2392+
<section id="section-11">
23802393
<h2 id="name-iana-considerations">
2381-
<a href="#section-10" class="section-number selfRef">10. </a><a href="#name-iana-considerations" class="section-name selfRef">IANA Considerations</a>
2394+
<a href="#section-11" class="section-number selfRef">11. </a><a href="#name-iana-considerations" class="section-name selfRef">IANA Considerations</a>
23822395
</h2>
23832396
<div id="oauth-parameters-registry">
2384-
<section id="section-10.1">
2397+
<section id="section-11.1">
23852398
<h3 id="name-oauth-parameters-registry">
2386-
<a href="#section-10.1" class="section-number selfRef">10.1. </a><a href="#name-oauth-parameters-registry" class="section-name selfRef">OAuth Parameters Registry</a>
2399+
<a href="#section-11.1" class="section-number selfRef">11.1. </a><a href="#name-oauth-parameters-registry" class="section-name selfRef">OAuth Parameters Registry</a>
23872400
</h3>
2388-
<p id="section-10.1-1">This specification registers the following parameter in the IANA "OAuth Parameters" registry <span>[<a href="#IANA.OAuth.Parameters" class="cite xref">IANA.OAuth.Parameters</a>]</span> established by <span>[<a href="#RFC6749" class="cite xref">RFC6749</a>]</span>.<a href="#section-10.1-1" class="pilcrow"></a></p>
2401+
<p id="section-11.1-1">This specification registers the following parameter in the IANA "OAuth Parameters" registry <span>[<a href="#IANA.OAuth.Parameters" class="cite xref">IANA.OAuth.Parameters</a>]</span> established by <span>[<a href="#RFC6749" class="cite xref">RFC6749</a>]</span>.<a href="#section-11.1-1" class="pilcrow"></a></p>
23892402
<div id="dcql-queries">
2390-
<section id="section-10.1.1">
2403+
<section id="section-11.1.1">
23912404
<h4 id="name-dcql_queries">
2392-
<a href="#section-10.1.1" class="section-number selfRef">10.1.1. </a><a href="#name-dcql_queries" class="section-name selfRef">dcql_queries</a>
2405+
<a href="#section-11.1.1" class="section-number selfRef">11.1.1. </a><a href="#name-dcql_queries" class="section-name selfRef">dcql_queries</a>
23932406
</h4>
23942407
<ul class="compact">
2395-
<li class="compact" id="section-10.1.1-1.1">Name: <code>dcql_queries</code><a href="#section-10.1.1-1.1" class="pilcrow"></a>
2408+
<li class="compact" id="section-11.1.1-1.1">Name: <code>dcql_queries</code><a href="#section-11.1.1-1.1" class="pilcrow"></a>
23962409
</li>
2397-
<li class="compact" id="section-10.1.1-1.2">Parameter Usage Location: authorization request, client metadata, and in <code>openid_credential_verifier</code> entity metadata as defined by this specification.<a href="#section-10.1.1-1.2" class="pilcrow"></a>
2410+
<li class="compact" id="section-11.1.1-1.2">Parameter Usage Location: authorization request, client metadata, and in <code>openid_credential_verifier</code> entity metadata as defined by this specification.<a href="#section-11.1.1-1.2" class="pilcrow"></a>
23982411
</li>
2399-
<li class="compact" id="section-10.1.1-1.3">Change Controller: OpenID Foundation AB/Connect Working Group - openid-specs-ab@lists.openid.net<a href="#section-10.1.1-1.3" class="pilcrow"></a>
2412+
<li class="compact" id="section-11.1.1-1.3">Change Controller: OpenID Foundation AB/Connect Working Group - openid-specs-ab@lists.openid.net<a href="#section-11.1.1-1.3" class="pilcrow"></a>
24002413
</li>
2401-
<li class="compact" id="section-10.1.1-1.4">Reference: Additional OpenID Credential Verifier Metadata Parameters section of this specification<a href="#section-10.1.1-1.4" class="pilcrow"></a>
2414+
<li class="compact" id="section-11.1.1-1.4">Reference: Additional OpenID Credential Verifier Metadata Parameters section of this specification<a href="#section-11.1.1-1.4" class="pilcrow"></a>
24022415
</li>
24032416
</ul>
24042417
</section>
@@ -2408,23 +2421,24 @@ <h4 id="name-dcql_queries">
24082421
</section>
24092422
</div>
24102423
<div id="acknowledgements">
2411-
<section id="section-11">
2424+
<section id="section-12">
24122425
<h2 id="name-acknowledgements">
2413-
<a href="#section-11" class="section-number selfRef">11. </a><a href="#name-acknowledgements" class="section-name selfRef">Acknowledgements</a>
2426+
<a href="#section-12" class="section-number selfRef">12. </a><a href="#name-acknowledgements" class="section-name selfRef">Acknowledgements</a>
24142427
</h2>
2415-
<p id="section-11-1">We would like to thank the following individuals for their comments, ideas, and contributions to this implementation profile and to the initial set of implementations:
2428+
<p id="section-12-1">We would like to thank the following individuals for their comments, ideas, and contributions to this implementation profile and to the initial set of implementations:
24162429
Leif Johansson,
24172430
Stefan Liström,
24182431
Francesco Antonio Marino,
24192432
Eduardo Perottoni,
2433+
Samuel Rinnetmäki,
24202434
Giada Sciarretta,
24212435
and
2422-
Niels van Dijk.<a href="#section-11-1" class="pilcrow"></a></p>
2436+
Niels van Dijk.<a href="#section-12-1" class="pilcrow"></a></p>
24232437
</section>
24242438
</div>
2425-
<section id="section-12">
2439+
<section id="section-13">
24262440
<h2 id="name-normative-references">
2427-
<a href="#section-12" class="section-number selfRef">12. </a><a href="#name-normative-references" class="section-name selfRef">Normative References</a>
2441+
<a href="#section-13" class="section-number selfRef">13. </a><a href="#name-normative-references" class="section-name selfRef">Normative References</a>
24282442
</h2>
24292443
<dl class="references">
24302444
<dt id="I-D.ietf-oauth-status-list">[I-D.ietf-oauth-status-list]</dt>
@@ -2437,7 +2451,7 @@ <h2 id="name-normative-references">
24372451
<dd class="break"></dd>
24382452
<dt id="OpenID.Federation">[OpenID.Federation]</dt>
24392453
<dd>
2440-
<span class="refAuthor">Ed., R. H.</span>, <span class="refAuthor">Jones, M. B.</span>, <span class="refAuthor">Solberg, A.</span>, <span class="refAuthor">Bradley, J.</span>, <span class="refAuthor">Marco, G. D.</span>, and <span class="refAuthor">V. Dzhuvinov</span>, <span class="refTitle">"OpenID Federation 1.0"</span>, <time datetime="2026-01-29" class="refDate">29 January 2026</time>, <span>&lt;<a href="https://openid.net/specs/openid-federation-1_0.html">https://openid.net/specs/openid-federation-1_0.html</a>&gt;</span>. </dd>
2454+
<span class="refAuthor">Ed., R. H.</span>, <span class="refAuthor">Jones, M. B.</span>, <span class="refAuthor">Solberg, A.</span>, <span class="refAuthor">Bradley, J.</span>, <span class="refAuthor">Marco, G. D.</span>, and <span class="refAuthor">V. Dzhuvinov</span>, <span class="refTitle">"OpenID Federation 1.0"</span>, <time datetime="2026-02-15" class="refDate">15 February 2026</time>, <span>&lt;<a href="https://openid.net/specs/openid-federation-1_0.html">https://openid.net/specs/openid-federation-1_0.html</a>&gt;</span>. </dd>
24412455
<dd class="break"></dd>
24422456
<dt id="OpenID.Registration">[OpenID.Registration]</dt>
24432457
<dd>
@@ -2485,9 +2499,9 @@ <h2 id="name-normative-references">
24852499
<dd class="break"></dd>
24862500
</dl>
24872501
</section>
2488-
<section id="section-13">
2502+
<section id="section-14">
24892503
<h2 id="name-informative-references">
2490-
<a href="#section-13" class="section-number selfRef">13. </a><a href="#name-informative-references" class="section-name selfRef">Informative References</a>
2504+
<a href="#section-14" class="section-number selfRef">14. </a><a href="#name-informative-references" class="section-name selfRef">Informative References</a>
24912505
</h2>
24922506
<dl class="references">
24932507
<dt id="IANA.OAuth.Parameters">[IANA.OAuth.Parameters]</dt>
@@ -2543,6 +2557,8 @@ <h2 id="name-document-history">
25432557
different situations.<a href="#appendix-B-3.8" class="pilcrow"></a>
25442558
</li>
25452559
<li class="compact" id="appendix-B-3.9">Added IANA Considerations registering the dcql_queries parameter.<a href="#appendix-B-3.9" class="pilcrow"></a>
2560+
</li>
2561+
<li class="compact" id="appendix-B-3.10">Added Security Considerations.<a href="#appendix-B-3.10" class="pilcrow"></a>
25462562
</li>
25472563
</ul>
25482564
<p id="appendix-B-4">-04<a href="#appendix-B-4" class="pilcrow"></a></p>

connect/openid-federation-wallet-1_0-05.md

Lines changed: 9 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -840,6 +840,12 @@ The Entity that receives the data object including the JWT `trust_chain`, such a
840840

841841
Using short-lived Trust Chains ensures compatibility with required revocation administrative protocols, such as those defined in a legal framework. For example, if a revocation must be propagated in less than 24 hours, the Trust Chain should not be valid for more than that period.
842842

843+
# Security Considerations
844+
845+
The security considerations in
846+
[@!OpenID.Federation], [@!OpenID4VP], and [@!OpenID4VCI]
847+
apply to this specification.
848+
843849
# IANA Considerations
844850

845851
## OAuth Parameters Registry
@@ -860,6 +866,7 @@ Leif Johansson,
860866
Stefan Liström,
861867
Francesco Antonio Marino,
862868
Eduardo Perottoni,
869+
Samuel Rinnetmäki,
863870
Giada Sciarretta,
864871
and
865872
Niels van Dijk.
@@ -994,7 +1001,7 @@ Niels van Dijk.
9941001
<author fullname="Vladimir Dzhuvinov">
9951002
<organization>Connect2id</organization>
9961003
</author>
997-
<date day="29" month="January" year="2026"/>
1004+
<date day="15" month="February" year="2026"/>
9981005
</front>
9991006
</reference>
10001007

@@ -1040,6 +1047,7 @@ The technology described in this specification was made available from contribut
10401047
OpenID4VP) so verifiers can publish multiple authorized queries for
10411048
different situations.
10421049
* Added IANA Considerations registering the dcql_queries parameter.
1050+
* Added Security Considerations.
10431051

10441052
-04
10451053

0 commit comments

Comments
 (0)