Skip to content

Commit 6bb7789

Browse files
committed
Trust anchor clarity in registration policies
Signed-off-by: steve lasker <[email protected]>
1 parent 7615e71 commit 6bb7789

File tree

1 file changed

+1
-3
lines changed

1 file changed

+1
-3
lines changed

draft-ietf-scitt-architecture.md

Lines changed: 1 addition & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -397,9 +397,7 @@ Multi-tenant support can be enabled through the use of identifiers in the `iss`
397397

398398
Registration Policies refer to additional checks over and above the Mandatory Registration Checks that are performed before a Signed Statement is accepted to be registered to the Append-only Log.
399399

400-
Transparency Services MUST maintain Registration Policies.
401-
402-
Transparency Services MUST also maintain a list of trust anchors, which SHOULD be used by Relying Parties to authenticate Issuers, and which MAY be included in a Registration Policy statement.
400+
Transparency Services MUST maintain Registration Policies and a list of trust anchors to authenticate Issuers upon Registration.
403401
For instance, a trust anchor could be an X.509 root certificate, a pointer to an OpenID Connect identity provider, or any other COSE-compatible trust anchor.
404402

405403
Registration Policies and trust anchors MUST be made transparent and available to all Relying Parties of the Transparency Service by registering them as Signed Statements on the Append-only Log, and distributing the associated Receipts.

0 commit comments

Comments
 (0)