Skip to content

Conversation

@rohe
Copy link
Collaborator

@rohe rohe commented Aug 6, 2025

The old value was invalid. Signatures could not be verified.

@rohe rohe requested review from peppelinux and selfissued August 6, 2025 20:00
@ubamrein
Copy link

Checked with our implementation, seems to work :)

Copy link
Member

@peppelinux peppelinux left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All ok but the constraints within the TA's EC

"eyJhbGciOiJSUzI1NiIsImtpZCI6ImNUaFlYM0pITmtNemVWOWFWVFJvWkVvdFdHcHFNV3BtT0VSVFZqTnBiV2syUkd0RVpsWjFPVWQ1ZHcifQ.eyJtZXRhZGF0YSI6IHsib3BlbmlkX2NyZWRlbnRpYWxfaXNzdWVyIjogeyJqd2tzIjogeyJrZXlzIjogW3sia3R5IjogIlJTQSIsICJraWQiOiAiUjJSelJYQTBSVkJ5ZHpGT1ZHMWZkV1JUTVRaM1lUUm1ObkUxVjNGZk1FMW9NVVpMZWtsaVkxTllPQSIsICJlIjogIkFRQUIiLCAibiI6ICI1SF9YaDd4Z0RXVHhRVmJKcW1PR3Vyb2tFOGtyMmUxS2dNV2NZT0E3NE9fMVBYZDJ1Z2p5SXE5dDFtVlBTdXd4LXR5U2syUEtwanAtLVdySG4zQTRVS0prdVIxMXpobWRMQnNVOFRPQkJ1NU1aOGF0RHVqZlJ3SUxYZEtzRVhrbHZhQjZQTFQ0emRab2RnQ3MwNUt5MmU1c2I1ejZfQ2lEcWdVVm5XUG1KTE1rZ3BCdFota01kX2xiOVNvb1psbGZVR2xUa3NhdUoyX2dWUS1WcEZVTVhZam9Kak54OTdldWthWW5SRW9DQzNUYV8tOGJjUm9zbHgyeHJJYnVfVUdWcWlwZU4zTlAtbWVmZjlWVFpXWU0zZ21vbHd1cG5NQ1hYaWlrY1I1VVNMVmcwZV9nejZPZm9SVkdLQVdJcFJSTFR6MmFpcXVrVkhaZFpYOXRObXowbXcifV19fSwgImZlZGVyYXRpb25fZW50aXR5IjogeyJvcmdhbml6YXRpb25fbmFtZSI6ICJPcGVuSUQgQ3JlZGVudGlhbCBJc3N1ZXIgZXhhbXBsZSIsICJvcmdhbml6YXRpb25fdXJpIjogImh0dHBzOi8vY3JlZGVudGlhbF9pc3N1ZXIuZXhhbXBsZS5vcmcvaG9tZSIsICJwb2xpY3lfdXJpIjogImh0dHBzOi8vY3JlZGVudGlhbF9pc3N1ZXIuZXhhbXBsZS5vcmcvcG9saWN5IiwgImxvZ29fdXJpIjogImh0dHBzOi8vY3JlZGVudGlhbF9pc3N1ZXIuZXhhbXBsZS5vcmcvc3RhdGljL2xvZ28uc3ZnIiwgImNvbnRhY3RzIjogWyJ0ZWNoQGNyZWRlbnRpYWxfaXNzdWVyLmV4YW1wbGUub3JnIl19fSwgImF1dGhvcml0eV9oaW50cyI6IFsiaHR0cHM6Ly9pbnRlcm1lZGlhdGUuZWlkYXMuZXhhbXBsZS5vcmciXSwgImp3a3MiOiB7ImtleXMiOiBbeyJrdHkiOiAiUlNBIiwgImtpZCI6ICJjVGhZWDNKSE5rTXplVjlhVlRSb1pFb3RXR3BxTVdwbU9FUlRWak5wYldrMlJHdEVabFoxT1VkNWR3IiwgIm4iOiAid3pGaVM0S0RpY1VoeWlBZU9wX0hxLUZISkpqMFpLY2dtZHRHaFNxVk4waU5OVHlxTF9PN1JHZTc0QzhEdmYzYzVndXJWRk5Ub0Z1N0dZUHpPTnJiNTNSNjNjOFFBRmk3MWRqaktJZS1mZTU1bnowZjFfdDc2Qk5LUHJlSUhYbWQ3VDAzWU5WWDJ6YmY3T2p6ZWRhSWh2OTQwajVmV1JLeEpYdGdtYWh0dDlIYTlhdW9EVzZMU09fVUNQWDRsT0hyS0QyRkdiMUVXLTRmME9TWVhyQ0ZXbDlaVXZWaTdkUjI4TWdCbFVuSWF4cjViZ3F5Y0VSTmJaR3M0dGhfZ0lSMHpQd0dZMFdhT185R01IajFIQkxjeTVCZmp1TXlDeGxxbUZqVkw2N1g2c1VoX3VYX2p6N1BzR0dsd2xYc0JuUk0wTktlbHRZNjBEV1VvTWVwclhLb0R3IiwgImUiOiAiQVFBQiJ9XX0sICJzdWIiOiAiaHR0cHM6Ly9jcmVkZW50aWFsX2lzc3Vlci5leGFtcGxlLm9yZyIsICJpc3MiOiAiaHR0cHM6Ly9jcmVkZW50aWFsX2lzc3Vlci5leGFtcGxlLm9yZyIsICJpYXQiOiAxNzU0MzAzMDc2LCAiZXhwIjogMTc1NDYwMzA3Nn0.Sl6d4pWromPG2-OWazgv2osy5obdpd-5b-0OEq-GD_fhDu89iKjDy0SppfqOr00uC0npiitOQYMRU_gRof1K1PYZtE_5G42BXC4GwFGzPoOeiwsyCIg2I79MphdFQG-LuNhWXwR36HZTu3jDS7aWMosPAKw6QDgn3C82m8CjBLegXc6qs9uh8x4d7onhKQeCOuFmuFd8d8KCOVE62JSVrKoofPNsK_jEMR7Qlzl7OcyT4iImmH1anupnent-fhCXGBDui-ZQ51mVLDNLsZ0x-LmWkx7L2xPlPQYqLCHo9fJWPmoLEYs-Sygr1keA5KirzwvGbwjvm_LYPTCaeqQzxg"
"eyJhbGciOiJSUzI1NiIsImtpZCI6ImNubHRkV05DU0VWTll6ZHRXVzVoYTJZNVNVbzBhWEJXT0MxeFkxODNhWGgyUzJ4TFJIaFlTbXhzTkEifQ.eyJzdWIiOiAiaHR0cHM6Ly9jcmVkZW50aWFsX2lzc3Vlci5leGFtcGxlLm9yZyIsICJqd2tzIjogeyJrZXlzIjogW3sia3R5IjogIlJTQSIsICJraWQiOiAiY1RoWVgzSkhOa016ZVY5YVZUUm9aRW90V0dwcU1XcG1PRVJUVmpOcGJXazJSR3RFWmxaMU9VZDVkdyIsICJuIjogInd6RmlTNEtEaWNVaHlpQWVPcF9IcS1GSEpKajBaS2NnbWR0R2hTcVZOMGlOTlR5cUxfTzdSR2U3NEM4RHZmM2M1Z3VyVkZOVG9GdTdHWVB6T05yYjUzUjYzYzhRQUZpNzFkampLSWUtZmU1NW56MGYxX3Q3NkJOS1ByZUlIWG1kN1QwM1lOVlgyemJmN09qemVkYUlodjk0MGo1ZldSS3hKWHRnbWFodHQ5SGE5YXVvRFc2TFNPX1VDUFg0bE9IcktEMkZHYjFFVy00ZjBPU1lYckNGV2w5WlV2Vmk3ZFIyOE1nQmxVbklheHI1YmdxeWNFUk5iWkdzNHRoX2dJUjB6UHdHWTBXYU9fOUdNSGoxSEJMY3k1QmZqdU15Q3hscW1GalZMNjdYNnNVaF91WF9qejdQc0dHbHdsWHNCblJNME5LZWx0WTYwRFdVb01lcHJYS29EdyIsICJlIjogIkFRQUIifV19LCAiaXNzIjogImh0dHBzOi8vaW50ZXJtZWRpYXRlLmVpZGFzLmV4YW1wbGUub3JnIiwgImlhdCI6IDE3NTQzMDMwNzYsICJleHAiOiAxNzU0NjAzMDc2fQ.fY_J-jRGxYBfwhfQqYtjbh0eEnfLdwM7adye64eI1pCK3NqV3a5kv5zqr-vr9l3DkU4swsDktmgfVbDZBhMpF52ftXzmTJ17LNYFEbzSs3OgivMGUxqy5AGrUS8tZRY3WAooIjkb_lMlz5awQ49vgmtXz5yaBnDnjIjktKJ9_lWVgQu7bN9KCx4MVAn1RekDqR-AIaJVPShUos4BMxANLbNB3DZtqRdeQMrMREGANTeVVV6lIo8sGPmpJnxiHLVxpKmgDFiM4PxGUdTpwc9I6BolLloBkT-11g3C7XcTZlFcnpFj5pMW7wwvsRkftVf91B_i0U4FGuXeTm9y7YoJOA"
"eyJhbGciOiJSUzI1NiIsImtpZCI6IlpYUkxYMHhrYms1SmFIaHpMWGRrY1ZaRGFsbE5OSFY0YVhFM2JuUkRlR2xyVFVWNlNIUkJiR3M0UVEifQ.eyJzdWIiOiAiaHR0cHM6Ly9pbnRlcm1lZGlhdGUuZWlkYXMuZXhhbXBsZS5vcmciLCAiandrcyI6IHsia2V5cyI6IFt7Imt0eSI6ICJSU0EiLCAia2lkIjogImNubHRkV05DU0VWTll6ZHRXVzVoYTJZNVNVbzBhWEJXT0MxeFkxODNhWGgyUzJ4TFJIaFlTbXhzTkEiLCAibiI6ICJ5Q3ctQ2RiVy1QRDZab1I3d3dCWVpVREhxRTVuY0tIYkhDZm1oS3BDY2lBVWY4UER4MGNfLU1Zakp3U1llSWdVZld2aDdNZUFzYVI4bWJ4OWpHMkZwZUpSMVh1cUpZWXFTNHNBVFk3RGxYenFIc255Ml9SSUdMY2ZiNnYxc0dBOC1UUmtlLUk2VEJfOVJwRGFyOVdYRE11YS11OHJVREZLR1N5RlF4b3RqS0RIYmV2RzlHUkVjaW16bkhMOEVLTlQwQTZsRlJqbDRKazJ2V3kxQzFJYXpRdWlJbXFVOGpidDNxSkV0cVltc1B2M2hSRktVRnJhdGh3bjhFOFdELTJpQVVvTlFvc0lDUVdUVHZCVEhITDllQm1Ibzd1M3NNRHdURkc1NW1LTU13WDZ3bF9tSHU5UEo1QmhZd0F1NDE2TU9pV0hhWmRtc0RmNGZVZm8xOXdFQXciLCAiZSI6ICJBUUFCIn1dfSwgImlzcyI6ICJodHRwczovL3RydXN0LWFuY2hvci5leGFtcGxlLm9yZyIsICJpYXQiOiAxNzU0MzAzMDc2LCAiZXhwIjogMTc1NDYwMzA3Nn0.nZ_iBKeX5VuY1d4qn7lMppeKq64kHim3a8VUona4It03Th08nnS7XiV0PIl5n82sLUeDIUwdfaIgYkDrMpWZKJ9OSfx0XacAm80_iz3eUqHgWgsC0xv501ESV4Kjohx8eHCbKLZG_lxCmFnYwD9hhFp66y5BX90aPvigSebg9nLQ7sqKa2Gnks-SZ1slWZ0k0E_rLhXxq2IhtY_ikjkJa2Lv13c_GB5TcgiZk0QyLSSjp-hQOX10hpvEcII0m-RZFvcSr9bRL3aKnXQpLkmUnOeIcyGtBjpm59X_qZtkrreRLBfbK_uHVsdsqLWSoA655bryIEChAl7f2C89zwhmPw"
"eyJhbGciOiJSUzI1NiIsImtpZCI6IlpYUkxYMHhrYms1SmFIaHpMWGRrY1ZaRGFsbE5OSFY0YVhFM2JuUkRlR2xyVFVWNlNIUkJiR3M0UVEifQ.eyJtZXRhZGF0YSI6IHsiZmVkZXJhdGlvbl9lbnRpdHkiOiB7ImZlZGVyYXRpb25fZmV0Y2hfZW5kcG9pbnQiOiAiaHR0cHM6Ly90cnVzdC1hbmNob3IuZXhhbXBsZS5vcmcvZmV0Y2giLCAiZmVkZXJhdGlvbl9yZXNvbHZlX2VuZHBvaW50IjogImh0dHBzOi8vdHJ1c3QtYW5jaG9yLmV4YW1wbGUub3JnL3Jlc29sdmUiLCAiZmVkZXJhdGlvbl9saXN0X2VuZHBvaW50IjogImh0dHBzOi8vdHJ1c3QtYW5jaG9yLmV4YW1wbGUub3JnL2xpc3QiLCAib3JnYW5pemF0aW9uX25hbWUiOiAiVEEgZXhhbXBsZSIsICJvcmdhbml6YXRpb25fdXJpIjogImh0dHBzOi8vdHJ1c3QtYW5jaG9yLmV4YW1wbGUub3JnL2hvbWUiLCAicG9saWN5X3VyaSI6ICJodHRwczovL3RydXN0LWFuY2hvci5leGFtcGxlLm9yZy9wb2xpY3kiLCAibG9nb191cmkiOiAiaHR0cHM6Ly90cnVzdC1hbmNob3IuZXhhbXBsZS5vcmcvc3RhdGljL2xvZ28uc3ZnIiwgImNvbnRhY3RzIjogWyJ0ZWNoQHRydXN0LWFuY2hvci5leGFtcGxlLm9yZyJdfX0sICJjb25zdHJhaW50cyI6IHsibWF4X3BhdGhfbGVuZ3RoIjogMX0sICJqd2tzIjogeyJrZXlzIjogW3sia3R5IjogIlJTQSIsICJraWQiOiAiWlhSTFgweGtiazVKYUhoekxYZGtjVlpEYWxsTk5IVjRhWEUzYm5SRGVHbHJUVVY2U0hSQmJHczRRUSIsICJuIjogIjNtZEtTZVVpUW1TVHNvT0xHbmw2MTkweTJaNmZ3SUctdG9XWjZUNWwyLXZ2ekhRTmtmSWFsSVRQXzZITkZEaXh0ZjliV1U4QlIwMVU2OEJ0MGItNmc5UEdhdEkxT19FN2hDeTFDOUJOSjI4MDA0c0ZOWW93N3RvOU9YRkxmMlN3c05hOXAzZmg3Uk5tTE1WZXVDUFdtTFB0cThJVk5FbS1SemNkNjlYYTJNbjItQV94eHRGclIteWNvWlFHWEhVdEZaVTQ5YW8xQmVFeHhoS25zajAwUDdZVUF1dHBHdFNYLWFOSDVrM2Q2RTN1S3UzeWdGN1lPSTNZYW5XWXFLNEo4d0pSRFZPU0ZHWVJncXJEYTRfVkR0dnM0cWxPYnhSSktjWlpCZTN3aG1ic1FTMm85d3RYUjVJTHY2X1J4SUV3Z3h6cUJORERhLWxFQVg4ZFZiRnh5USIsICJlIjogIkFRQUIifV19LCAic3ViIjogImh0dHBzOi8vdHJ1c3QtYW5jaG9yLmV4YW1wbGUub3JnIiwgImlzcyI6ICJodHRwczovL3RydXN0LWFuY2hvci5leGFtcGxlLm9yZyIsICJpYXQiOiAxNzU0MzAzMDc2LCAiZXhwIjogMTc1NDYwMzA3Nn0.GyMkrSar7eeQwdeZKeOfAw3RheHEIbSs34eawDNKZ2MZ4nZq4KFhxKdYsDGHk9RzqX7ZWfL0319sfXAk4Txw8jg0qzXQBgHY8j-WDgdU3KOCF-oYJ9f_-BxngjHscbxcgmS6FpEFylCZ28pWOJq0Sd2YYwp7LkcfgGeVeXxmLEtac14xPlBCui8xUCVP7OCoqGSYm2wK45lQCJdkBp99HRJ5LTd_d_BZLceWGgIko1ELVPgCnN9JlkoHghIdNP9cKfkV1R7ZK87c1_9beacqUwmqhbSGmLw8_hCEfq7LTRZRY_eMfMl1UWtJdYDLpTTEV3ayLL1CAmr7g6qEabalfQ"
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

constraints should not be provided within the TA's EC, according to last drafts

@ubamrein
Copy link

Just realised, shouldn't the JWTs be typed (e.g. entity-statement+jwt) according to https://openid.net/specs/openid-federation-1_0.html#name-entity-statement?

@selfissued selfissued merged commit 882ff70 into main Aug 18, 2025
1 check passed
@ubamrein
Copy link

Ahm so the header of the JWTs

(e.g.
eyJhbGciOiJSUzI1NiIsImtpZCI6IlNDMXBkbXhuUlRJNWFUSlRkRXQ0WjJaWVJtc3lObWhZTTI1TlQzTTVVM1YyTlVKUVptTTNaR3hIVFEifQ

{
  "alg": "RS256",
  "kid": "SC1pdmxnRTI5aTJTdEt4Z2ZYRmsyNmhYM25NT3M5U3V2NUJQZmM3ZGxHTQ"
}

)

Don't contain a typ claim. But Section 3 https://openid.net/specs/openid-federation-1_0.html#name-entity-statement mandates one. Shouldn't that be adjusted as well?

@rohe
Copy link
Collaborator Author

rohe commented Sep 20, 2025

I'll construct another PR to fix the missing typ claim.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants