Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Note subdomain config differentiation #365

Merged
merged 3 commits into from May 16, 2023
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Jump to
Jump to file
Failed to load files.
Diff view
Diff view
6 changes: 6 additions & 0 deletions draft-ietf-privacypass-protocol.md
Expand Up @@ -195,6 +195,12 @@ Issuer directory resources have the media type
/.well-known/token-issuer-directory; see {{wkuri-reg}} for the registration
information for this well-known URI.

The issuer directory and issuer resources SHOULD be available on the same domain. If
an Issuer wants to service multiple different issuer directories they MUST create
unique subdomains for each so the TokenChallenge defined in
{{Section 2.1 of !AUTHSCHEME=I-D.ietf-privacypass-auth-scheme}} can be
differentiated correctly.

Issuers SHOULD use HTTP caching to permit caching of this resource
{{!RFC5861}}. The cache lifetime depends on the Issuer's key rotation schedule.
Regular rotation of token keys is recommended to minimize the risk of key
Expand Down