Skip to content

Conversation

@selfissued
Copy link
Member

Fixes #100

@rohe
Copy link
Collaborator

rohe commented Nov 12, 2025

In section 12.2 Explicit Registration it is stated that an RP can submit its Entity Configuration or an entire Trust Chain.

If submitting the Trust Chain the Entity Statement representing the RPs Entity Configuration could contain the peer_trust_chain and that Trust Chain would then be matched (to verify that they both ends at the same TA) against the submitted Trust Chain.

On the other hand if the RP decides to submit the Entity Configuration there is no Trust Chain for the RP in the request so no matching could be preformed.

I think you there for would have to add trust_chain to the registration request claims with the proviso that it should only be added if the request contained the Entity Configuration and not the entire Trust Chain.

@selfissued selfissued merged commit 86e6198 into main Nov 19, 2025
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Trust Anchor Mix-Up (Federation Integrity Property)

4 participants