Skip to content

Nonce length issue in SL1 OIDC profile #70

@dhs-BI

Description

@dhs-BI

While reviewing the IETF keyword changes, I noted an issue with the nonce length requirements. See openid/ipsie-openid-sl1#1 (comment) and openid/ipsie-openid-sl1#1 (comment).

As written today, the OpenID Providers section states:

shall support nonce parameter values up to 64 characters in length, may reject nonce values longer than 64 characters.

While the RP section states:

should not use nonce parameter values longer than 64 characters;

These two statements need to be aligned. I suggest the minimum length of 64 characters is acceptable and recommend adding a max length (e.g. 128 chars).

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions