create section saying how to verify distributed/aggregated claims

Issue #1333 resolved
Joseph Heenan created an issue

Vaguely related to https://bitbucket.org/openid/ekyc-ida/pull-requests/149 - we should probably create a new section saying how to verify distributed/aggregated claims.

It would be following the kind of precedent set in https://openid.net/specs/openid-connect-core-1_0.html#IDTokenValidation

And would say things like ‘must check typ header is xxx, must check signature (if that’s necessary, it’s sometimes not if the token is received over TLS…),must check <…>’.

Comments (9)

  1. Mark Haine

    Do we expect embedded attachements to be structured objects themselves in some cases? If so then we may need to state that an embedded structured object should/must be validated in the following way…

  2. Mark Haine

    Should we require that external attachments are only locations accessible via the “https” scheme?

  3. Log in to comment