Skip to content

Commit

Permalink
Merge pull request #365 from smhendrickson/patch-2
Browse files Browse the repository at this point in the history
Note subdomain config differentiation
  • Loading branch information
tfpauly committed May 16, 2023
2 parents 9f680c5 + ae5e298 commit 90bf8b9
Showing 1 changed file with 6 additions and 0 deletions.
6 changes: 6 additions & 0 deletions draft-ietf-privacypass-protocol.md
Expand Up @@ -195,6 +195,12 @@ Issuer directory resources have the media type
/.well-known/token-issuer-directory; see {{wkuri-reg}} for the registration
information for this well-known URI.

The issuer directory and issuer resources SHOULD be available on the same domain. If
an Issuer wants to service multiple different issuer directories they MUST create
unique subdomains for each so the TokenChallenge defined in
{{Section 2.1 of !AUTHSCHEME=I-D.ietf-privacypass-auth-scheme}} can be
differentiated correctly.

Issuers SHOULD use HTTP caching to permit caching of this resource
{{!RFC5861}}. The cache lifetime depends on the Issuer's key rotation schedule.
Regular rotation of token keys is recommended to minimize the risk of key
Expand Down

0 comments on commit 90bf8b9

Please sign in to comment.