Unsigned error response

Issue #1703 resolved
Roland Hedberg created an issue

One of the foundational design criteria with OIDC Federation was to have end-to-end protection of messages that was not dependent on TLS.

There is one response message that is not protected by an issuer signature and that is the error message.

After discussion between the editors we have decided to add a security consideration describing possible threats that appear as a result of this.