- changed status to open
Make clear that requests and responses to resource servers don't have to be bound
Issue #608
resolved
i.e. it is possible to have a signed request, but not a signed response
and its also possible to have a signed response without a signed request
Comments (5)
-
-
What is the status on this? The current draft still mandates the RS to
cryptographically link the response to the request
(Sec. 5.6.2.1 No. 2). Is the plan to basically change theshall
in that clause to amay
? -
reporter make it clear to only sign request signature and request signature input if applicable (i.e. if present)
also add to the note to explain further -
reporter -
reporter - changed status to resolved
PR merged
- Log in to comment