Reader authentication x509 certificate header - #65
martijnharing wants to merge 1 commit into
Conversation
Resolves #51 Added section on public key authentication methods, specifically X.509 certificates, and their inclusion in COSE_Signature structure.
|
📄 Editor's Copy preview Preview of cdb307d; updated on every push. For review only — the official specifications are published at https://openid.net/specs/ |
|
Discussed on today's WG call; no feedback, Christian & Andreea offered to review. Some discussions about the use of the terms verifier vs reader - Matt offered to open an issue on that, that's #67 |
| ## Public key authentication ## | ||
|
|
||
| This document specifies the following methods to authenticate the public key used for reader authentication: | ||
| - X.509 certificate |
There was a problem hiding this comment.
needs another empty line to render properly
| - X.509 certificate | |
| - X.509 certificate |
|
|
||
| Other mechanisms may be used and are out of scope of this document. | ||
|
|
||
| When using an X.509 certificate to authenticate the reader authentication public key, that certificate shall be included as an x5chain element in the protected header of the COSE_Signature structure. The x5chain element shall contain at least 1 certificate and may contain more. The x5chain element is defined in RFC 9360. |
There was a problem hiding this comment.
Since we are using COSE_Sign, we should probably allow multiple signatures here and reformulate a bit?
| When using an X.509 certificate to authenticate the reader authentication public key, that certificate shall be included as an x5chain element in the protected header of the COSE_Signature structure. The x5chain element shall contain at least 1 certificate and may contain more. The x5chain element is defined in RFC 9360. | |
| When using an X.509 certificate to authenticate the reader authentication public key, that certificate shall be included as an x5chain element in the protected header of the COSE_Signature structure whose signature is verified with that public key. | |
| The x5chain element shall contain at least one certificate, encoded and ordered as specified in RFC 9360. The first certificate shall contain the reader authentication public key. |
|
|
||
| ## Public key authentication ## | ||
|
|
||
| This document specifies the following methods to authenticate the public key used for reader authentication: |
There was a problem hiding this comment.
| This document specifies the following methods to authenticate the public key used for reader authentication: | |
| This document specifies the following methods to convey the public key used for reader authentication: |
There was a problem hiding this comment.
I suggest convey , since the main idea here is that the reader public key is transported in a certificate.
In other cases we could transport it in other type of signed attestations, while still using X509 certificates to authenticate those attestations.
|
|
||
| Other mechanisms may be used and are out of scope of this document. | ||
|
|
||
| When using an X.509 certificate to authenticate the reader authentication public key, that certificate shall be included as an x5chain element in the protected header of the COSE_Signature structure. The x5chain element shall contain at least 1 certificate and may contain more. The x5chain element is defined in RFC 9360. |
There was a problem hiding this comment.
| When using an X.509 certificate to authenticate the reader authentication public key, that certificate shall be included as an x5chain element in the protected header of the COSE_Signature structure. The x5chain element shall contain at least 1 certificate and may contain more. The x5chain element is defined in RFC 9360. | |
| When using an X.509 certificate to convey the reader authentication public key, that certificate shall be included as an x5chain element in the protected header of the COSE_Signature structure. The x5chain element shall contain at least 1 certificate and may contain more. The x5chain element is defined in RFC 9360. |
Resolves #51
Added section on public key authentication methods, specifically X.509 certificates, and their inclusion in COSE_Signature structure.