Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

ID Token algorithm support requirements are ambiguous #491

Closed
CDR-API-Stream opened this issue Mar 17, 2022 · 1 comment
Closed

ID Token algorithm support requirements are ambiguous #491

CDR-API-Stream opened this issue Mar 17, 2022 · 1 comment
Labels
Documentation Improvements, additions or queries related to documentation Security Change or question related to the information security profile

Comments

@CDR-API-Stream
Copy link
Collaborator

Description

In the translation of ID Token Algorithm Selection Considerations from the Register design to the CDS the requirement for each participant type are not clearly defined and adds confusion to the differing support requirements for each participant type.

  • Data holders must support at a minimum, 1 algorithm for each claim.
  • Data Recipients must support all the algorithms used in the ecosystem to ensure they can communicate with all Data Holders.

Clarification on this topic was provided 2 years ago: ConsumerDataStandardsAustralia/register#97

Area Affected

Client Registration > ID Token Algorithm Selection Considerations

Change Proposed

The CDS needs to be updated so these requirements are clear.

We don’t anticipate any FDOs for this change as this requirement is already being met in production, and would be considered a non-breaking change

@CDR-API-Stream CDR-API-Stream added Documentation Improvements, additions or queries related to documentation Security Change or question related to the information security profile change request labels Mar 17, 2022
@CDR-API-Stream
Copy link
Collaborator Author

This issue has been staged at: ConsumerDataStandardsAustralia/standards-staging#199

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Documentation Improvements, additions or queries related to documentation Security Change or question related to the information security profile
Projects
Archived in project
Development

No branches or pull requests

2 participants