[Federation] The federation_trust_mark_endpoint requires a "sub" request parameter

Issue #2128 resolved
Vladimir Dzhuvinov created an issue

In a recent spec update private_key_jwt authentication at the Trust Mark endpoint was made optional. Previously the JWT sub claim was used to determine the Trust Mark subject. Now we are going to need an explicit sub parameter to convey the subject, designated as REQUIRED.

https://openid.bitbucket.io/connect/openid-federation-1_0.html#tm_endpoint