Skip to content

[Discovery fearture] Is issuer the right attribute in the Metadata document? #299

@identitymonk

Description

@identitymonk

I open this issue on behalf of @baboulebou following WG meeting of April 22nd.

Proposal for PDP metadata document includes the following attribute:

issuer:

    REQUIRED. The policy decision point's issuer identifier, which is a URL that
uses the "https" scheme and has no query or fragment components. Policy
Decision Point metadata is published at a location that is ".well-known" according
to [[RFC5785](l#RFC5785)] derived from this issuer identifier, as described in
[Section 11.2](#pdp-metadata-access). The issuer identifier is used to prevent
policy decision point mix-up attacks.

This is an outcome of basing this proposal on OAuth 2.0 Authorization Server Metadata and OAuth 2.0 Protected Resource Metadata.

The discussion here is: is issuer the right attribute name knowing that its definition will require a IANA registration.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions