Difference between revisions of "Entity Statement"
From MgmtWiki
(→Solutions) |
(→Solutions) |
||
| Line 19: | Line 19: | ||
| iat || || || The time the statement was issued. | | iat || || || The time the statement was issued. | ||
|- | |- | ||
| − | | exp || || || Expiration time | + | | exp || || || Expiration time when the statement MUST NOT be used for new signatures |
|- | |- | ||
| jwks || || || public part of the subject entity's signing keys | | jwks || || || public part of the subject entity's signing keys | ||
Revision as of 23:05, 21 June 2019
Full Title or Meme
A digital document that describes a digital Entity typically signed by a trusted issuer.
Context
On the Identity Management page different roles are defined for Entities.
Problems
Solutions
Quite a few structures have been defined to describe entities. The Entity Statement created in the OpenID Connect Federation document is taken as be base for comparison with several others in the table below.
| Entity Statement | X.509 certificate | DID Document | Notes |
| iss | The entity identifier of the issuer of the statement. | ||
| sub | The entity identifier of the subject | ||
| iat | The time the statement was issued. | ||
| exp | Expiration time when the statement MUST NOT be used for new signatures | ||
| jwks | public part of the subject entity's signing keys | ||
| authority_hints | entities that may issue an entity statement about the issuer entity | ||
| metadata | protocol specific metadata claims | ||
| metadata_policy | type followed by organization information | ||
| sub_is_leaf | is the subject considered a leaf entity | ||
| a | |||
| b | |||
| c |