Skip to content

Commit

Permalink
Update draft-ietf-scitt-architecture.md
Browse files Browse the repository at this point in the history
Co-authored-by: Orie Steele <[email protected]>
  • Loading branch information
SteveLasker and OR13 authored Oct 8, 2024
1 parent 6bb7789 commit f38f8bb
Showing 1 changed file with 3 additions and 1 deletion.
4 changes: 3 additions & 1 deletion draft-ietf-scitt-architecture.md
Original file line number Diff line number Diff line change
Expand Up @@ -397,7 +397,9 @@ Multi-tenant support can be enabled through the use of identifiers in the `iss`

Registration Policies refer to additional checks over and above the Mandatory Registration Checks that are performed before a Signed Statement is accepted to be registered to the Append-only Log.

Transparency Services MUST maintain Registration Policies and a list of trust anchors to authenticate Issuers upon Registration.
Transparency Services MUST maintain Registration Policies.
Transparency Services MUST maintain a list of trust anchors as described in _TBD_.
Transparency Services MUST authenticate signed statements as part of a Registration Policy.
For instance, a trust anchor could be an X.509 root certificate, a pointer to an OpenID Connect identity provider, or any other COSE-compatible trust anchor.

Registration Policies and trust anchors MUST be made transparent and available to all Relying Parties of the Transparency Service by registering them as Signed Statements on the Append-only Log, and distributing the associated Receipts.
Expand Down

0 comments on commit f38f8bb

Please sign in to comment.