[Federation] Request object sub claim

Issue #1535 resolved
Giuseppe De Marco created an issue

in Section “10.1.1.1. Using a Request Object” we have several costrinctions about how to compose the Request object (for automatic client registration).

One of these prevents the usage of the claim sub.
However in the non normative example we found the sub claim.

I’d suggest to remove the constraint that prevents the usage of the sub claim, if present it will be simply ignored by OPs that will only look for the client_id claim.

Comments (6)

  1. Giuseppe De Marco reporter

    Having jti I think that the reuse of the request object as private_key_jwt would not possible anyway

  2. Giuseppe De Marco reporter

    Ok, I cant see the need to reuse this AR JWT as private_key_jwt.

    This means that this issue would only address the presence of the sub claim in the normative example

  3. Giuseppe De Marco reporter

    And probably this should be mentioned in the security considerations @Michael Jones @Roland Hedberg

  4. Log in to comment