Skip to content

Commit 0867983

Browse files
author
ID Bot
committed
Script updating gh-pages from 78d5bd8. [ci skip]
1 parent ab34c41 commit 0867983

2 files changed

Lines changed: 122 additions & 129 deletions

File tree

312-genart-review-p2/draft-ietf-oauth-status-list.html

Lines changed: 53 additions & 50 deletions
Original file line numberDiff line numberDiff line change
@@ -1950,7 +1950,7 @@ <h3 id="name-status-list-token-in-jwt-fo">
19501950
<h3 id="name-status-list-token-in-cwt-fo">
19511951
<a href="#section-5.2" class="section-number selfRef">5.2. </a><a href="#name-status-list-token-in-cwt-fo" class="section-name selfRef">Status List Token in CWT Format</a>
19521952
</h3>
1953-
<p id="section-5.2-1">The Status List Token <span class="bcp14">MUST</span> be encoded as a "CBOR Web Token (CWT)" according to <span>[<a href="#RFC8392" class="cite xref">RFC8392</a>]</span>.<a href="#section-5.2-1" class="pilcrow"></a></p>
1953+
<p id="section-5.2-1">The Status List Token <span class="bcp14">MUST</span> be encoded as a "CBOR Web Token (CWT)" according to <span>[<a href="#RFC8392" class="cite xref">RFC8392</a>]</span>. The Status List Token <span class="bcp14">MUST</span> not be tagged with the tags defined in section 6 of <span>[<a href="#RFC8392" class="cite xref">RFC8392</a>]</span> or in section 2 of <span>[<a href="#RFC9052" class="cite xref">RFC9052</a>]</span>.<a href="#section-5.2-1" class="pilcrow"></a></p>
19541954
<p id="section-5.2-2">The following content applies to the protected header of the CWT:<a href="#section-5.2-2" class="pilcrow"></a></p>
19551955
<ul class="normal">
19561956
<li class="normal" id="section-5.2-3.1">
@@ -1993,42 +1993,40 @@ <h3 id="name-status-list-token-in-cwt-fo">
19931993
<p id="section-5.2-8">The following is a non-normative example of a Status List Token in CWT format in Hex:<a href="#section-5.2-8" class="pilcrow"></a></p>
19941994
<div class="alignLeft art-text artwork" id="section-5.2-9">
19951995
<pre>
1996-
d2845820a2012610781a6170706c69636174696f6e2f7374617475736c6973742b63
1997-
7774a1044231325850a502782168747470733a2f2f6578616d706c652e636f6d2f73
1998-
74617475736c697374732f31061a648c5bea041a8898dfea19fffe19a8c019fffda2
1999-
646269747301636c73744a78dadbb918000217015d5840a530ad30f333deb22a0552
2000-
928f6283f3c3ac0b8431c353382dd4579faf2b62a8d4ec9b68bdb2fe2e92eb827058
2001-
c5fa91271b0afa53902f57805a5c1a57218357
1996+
845820a2012610781a6170706c69636174696f6e2f7374617475736c6973742b6377
1997+
74a1044231325850a502782168747470733a2f2f6578616d706c652e636f6d2f7374
1998+
617475736c697374732f31061a648c5bea041a8898dfea19fffe19a8c019fffda264
1999+
6269747301636c73744a78dadbb918000217015d58405c7f6ba7ac3039b18e980e2a
2000+
c3b1391517da73dccb721a074b4395677828150cdf236ac72f039ee9620afcf44b25
2001+
83a12bf3f1fb2d72cb7f4148d29290c64e62
20022002
</pre><a href="#section-5.2-9" class="pilcrow"></a>
20032003
</div>
20042004
<p id="section-5.2-10">The following is the CBOR Annotated Hex output of the example above:<a href="#section-5.2-10" class="pilcrow"></a></p>
20052005
<div class="alignLeft art-text artwork" id="section-5.2-11">
20062006
<pre>
2007-
d2 # tag(18)
2008-
84 # array(4)
2009-
58 20 # bytes(32)
2010-
a2012610781a6170706c6963 # "¢\x01&amp;\x10x\x1aapplic"
2011-
6174696f6e2f737461747573 # "ation/status"
2012-
6c6973742b637774 # "list+cwt"
2013-
a1 # map(1)
2014-
04 # uint(4)
2015-
42 # bytes(2)
2016-
3132 # "12"
2017-
58 50 # bytes(80)
2018-
a502782168747470733a2f2f # "¥\x02x!https://"
2019-
6578616d706c652e636f6d2f # "example.com/"
2020-
7374617475736c697374732f # "statuslists/"
2021-
31061a648c5bea041a8898df # "1\x06\x1ad\x8c[ê\x04\x1a\x88\x98ß"
2022-
ea19fffe19a8c019fffda264 # "ê\x19ÿþ\x19¨À\x19ÿý¢d"
2023-
6269747301636c73744a78da # "bits\x01clstJxÚ"
2024-
dbb918000217015d # "Û¹\x18\x00\x02\x17\x01]"
2025-
58 40 # bytes(64)
2026-
a530ad30f333deb22a055292 # "¥0\xad0ó3Þ²*\x05R\x92"
2027-
8f6283f3c3ac0b8431c35338 # "\x8fb\x83óì\x0b\x841ÃS8"
2028-
2dd4579faf2b62a8d4ec9b68 # "-ÔW\x9f¯+b¨Ôì\x9bh"
2029-
bdb2fe2e92eb827058c5fa91 # "½²þ.\x92ë\x82pXÅú\x91"
2030-
271b0afa53902f57805a5c1a # "'\x1b\x0aúS\x90/W\x80Z\\x1a"
2031-
57218357 # "W!\x83W"
2007+
84 # array(4)
2008+
58 20 # bytes(32)
2009+
a2012610781a6170706c696361 # "¢\x01&amp;\x10x\x1aapplica"
2010+
74696f6e2f7374617475736c69 # "tion/statusli"
2011+
73742b637774 # "st+cwt"
2012+
a1 # map(1)
2013+
04 # uint(4)
2014+
42 # bytes(2)
2015+
3132 # "12"
2016+
58 50 # bytes(80)
2017+
a502782168747470733a2f2f65 # "¥\x02x!https://e"
2018+
78616d706c652e636f6d2f7374 # "xample.com/st"
2019+
617475736c697374732f31061a # "atuslists/1\x06\x1a"
2020+
648c5bea041a8898dfea19fffe # "d\x8c[ê\x04\x1a\x88\x98ßê\x19ÿþ"
2021+
19a8c019fffda2646269747301 # "\x19¨À\x19ÿý¢dbits\x01"
2022+
636c73744a78dadbb918000217 # "clstJxÚÛ¹\x18\x00\x02\x17"
2023+
015d # "\x01]"
2024+
58 40 # bytes(64)
2025+
5c7f6ba7ac3039b18e980e2ac3 # "\\x7fk§¬09±\x8e\x98\x0e*Ã"
2026+
b1391517da73dccb721a074b43 # "±9\x15\x17ÚsÜËr\x1a\x07KC"
2027+
95677828150cdf236ac72f039e # "\x95gx(\x15\x0cß#jÇ/\x03\x9e"
2028+
e9620afcf44b2583a12bf3f1fb # "éb\x0aüôK%\x83¡+óñû"
2029+
2d72cb7f4148d29290c64e62 # "-rË\x7fAHÒ\x92\x90ÆNb"
20322030
</pre><a href="#section-5.2-11" class="pilcrow"></a>
20332031
</div>
20342032
</section>
@@ -2179,9 +2177,9 @@ <h4 id="name-cbor-web-token-cwt">
21792177
d28443a10126a1044231325866a502653132333435017368747470733a2f2f657861
21802178
6d706c652e636f6d061a648c5bea041a8898dfea19ffffa16b7374617475735f6c69
21812179
7374a2636964780063757269782168747470733a2f2f6578616d706c652e636f6d2f
2182-
7374617475736c697374732f315840663f6bbeb83485db8bb3b57f6e1b784c38b239
2183-
44391057288d70d044e6fa34b77fa43f8a52709c4ac48749bc0e87294abd278a7434
2184-
576ef49df5bffcc72c18c7
2180+
7374617475736c697374732f315840f2f66d27b0ab897d67988cc99fda7f1702980c
2181+
eb8c7187623d6b66016b0a692fe841edb254568fa8d7812ae4b9a3b86952ea746733
2182+
e31dc323bb1b2c9e086627
21852183
</pre><a href="#section-6.3.1-5" class="pilcrow"></a>
21862184
</div>
21872185
<p id="section-6.3.1-6">The following is the CBOR Annotated Hex output of the example above:<a href="#section-6.3.1-6" class="pilcrow"></a></p>
@@ -2206,12 +2204,12 @@ <h4 id="name-cbor-web-token-cwt">
22062204
2e636f6d2f7374617475736c # ".com/statusl"
22072205
697374732f31 # "ists/1"
22082206
58 40 # bytes(64)
2209-
663f6bbeb83485db8bb3b57f # "f?k¾¸4\x85Û\x8b³µ\x7f"
2210-
6e1b784c38b2394439105728 # "n\x1bxL8²9D9\x10W("
2211-
8d70d044e6fa34b77fa43f8a # "\x8dpÐDæú4·\x7f¤?\x8a"
2212-
52709c4ac48749bc0e87294a # "Rp\x9cJÄ\x87I¼\x0e\x87)J"
2213-
bd278a7434576ef49df5bffc # "½'\x8at4Wnô\x9dõ¿ü"
2214-
c72c18c7 # "Ç,\x18Ç"
2207+
f2f66d27b0ab897d67988cc9 # "òöm'°«\x89}g\x98\x8cÉ"
2208+
9fda7f1702980ceb8c718762 # "\x9fÚ\x7f\x17\x02\x98\x0cë\x8cq\x87b"
2209+
3d6b66016b0a692fe841edb2 # "=kf\x01k\x0ai/èAí²"
2210+
54568fa8d7812ae4b9a3b869 # "TV\x8f¨×\x81*ä¹£¸i"
2211+
52ea746733e31dc323bb1b2c # "Rêtg3ã\x1dÃ#»\x1b,"
2212+
9e086627 # "\x9e\x08f'"
22152213
</pre><a href="#section-6.3.1-7" class="pilcrow"></a>
22162214
</div>
22172215
</section>
@@ -2434,8 +2432,8 @@ <h3 id="name-status-list-request">
24342432
yJleHAiOjIyOTE3MjAxNzAsImlhdCI6MTY4NjkyMDE3MCwiaXNzIjoiaHR0cHM6Ly9le
24352433
GFtcGxlLmNvbSIsInN0YXR1c19saXN0Ijp7ImJpdHMiOjEsImxzdCI6ImVOcmJ1UmdBQ
24362434
WhjQlhRIn0sInN1YiI6Imh0dHBzOi8vZXhhbXBsZS5jb20vc3RhdHVzbGlzdHMvMSIsI
2437-
nR0bCI6NDMyMDB9.Mdkf1qFeeWwW1WXT8Ftgo4AezNu4-Jn5r9NS2-rss4iXrJSM3wrb
2438-
7bO4vdwQvCBNo8NtY7nZqWHt9syuGmH0-w
2435+
nR0bCI6NDMyMDB9.HYsyejZgF6k3CtBKrMLbvuMRpz7NWBYx-CJD_DF-hi2b4rdnopKu
2436+
ScGmmdai8obP7jWqOW6JhC_EbVx41tK3ow
24392437
</pre><a href="#section-8.1-10" class="pilcrow"></a>
24402438
</div>
24412439
</section>
@@ -2542,8 +2540,8 @@ <h3 id="name-historical-resolution">
25422540
yJleHAiOjIyOTE3MjAxNzAsImlhdCI6MTY4NjkyMDE3MCwiaXNzIjoiaHR0cHM6Ly9le
25432541
GFtcGxlLmNvbSIsInN0YXR1c19saXN0Ijp7ImJpdHMiOjEsImxzdCI6ImVOcmJ1UmdBQ
25442542
WhjQlhRIn0sInN1YiI6Imh0dHBzOi8vZXhhbXBsZS5jb20vc3RhdHVzbGlzdHMvMSIsI
2545-
nR0bCI6NDMyMDB9.Mdkf1qFeeWwW1WXT8Ftgo4AezNu4-Jn5r9NS2-rss4iXrJSM3wrb
2546-
7bO4vdwQvCBNo8NtY7nZqWHt9syuGmH0-w
2543+
nR0bCI6NDMyMDB9.HYsyejZgF6k3CtBKrMLbvuMRpz7NWBYx-CJD_DF-hi2b4rdnopKu
2544+
ScGmmdai8obP7jWqOW6JhC_EbVx41tK3ow
25472545
</pre><a href="#section-8.4-7" class="pilcrow"></a>
25482546
</div>
25492547
</section>
@@ -2810,7 +2808,7 @@ <h3 id="name-issuer-tracking-of-referenc">
28102808
<h3 id="name-observability-of-relying-pa">
28112809
<a href="#section-12.3" class="section-number selfRef">12.3. </a><a href="#name-observability-of-relying-pa" class="section-name selfRef">Observability of Relying Parties</a>
28122810
</h3>
2813-
<p id="section-12.3-1">Once the Relying Party receives the Referenced Token, the Relying Party can request the Status List through the provided <code>uri</code> parameter and can validate the Referenced Token's status by looking up the corresponding <code>index</code>. However, the Relying Party may persistently store the <code>uri</code> and <code>index</code> of the Referenced Token to request the Status List again at a later time. By doing so regularly, the Relying Party may create a profile of the Referenced Token's validity status. This behaviour may be intended as a feature, e.g. for an identity proofing (e.g. Know-Your-Customer process in finance industry) that requires regular validity checks, but might also be abused in cases where this is not intended and unknown to the Holder, e.g. profiling the suspension of a driving license or checking the employment status of an employee credential.<a href="#section-12.3-1" class="pilcrow"></a></p>
2811+
<p id="section-12.3-1">Once the Relying Party receives the Referenced Token, the Relying Party can request the Status List through the provided <code>uri</code> parameter and can validate the Referenced Token's status by looking up the corresponding <code>index</code>. However, the Relying Party may persistently store the <code>uri</code> and <code>index</code> of the Referenced Token to request the Status List again at a later time. By doing so regularly, the Relying Party may create a profile of the Referenced Token's validity status. This behaviour may be intended as a feature, e.g. for an identity proofing (e.g. Know-Your-Customer process in finance industry) that requires regular validity checks, but might also be abused in cases where this is not intended and unknown to the Holder, e.g. profiling the suspension of an employee credential.<a href="#section-12.3-1" class="pilcrow"></a></p>
28142812
<p id="section-12.3-2">This behaviour could be mitigated by:<a href="#section-12.3-2" class="pilcrow"></a></p>
28152813
<ul class="normal">
28162814
<li class="normal" id="section-12.3-3.1">
@@ -2905,8 +2903,7 @@ <h3 id="name-status-types-2">
29052903
<a href="#section-12.8" class="section-number selfRef">12.8. </a><a href="#name-status-types-2" class="section-name selfRef">Status Types</a>
29062904
</h3>
29072905
<p id="section-12.8-1">As previously explained, there is the potential risk of observability by Relying Parties (see <a href="#privacy-relying-party" class="auto internal xref">Section 12.3</a>) and Outsiders (see <a href="#privacy-outsider" class="auto internal xref">Section 12.4</a>). That means that any Status Type that transports information beyond the routine statuses VALID and INVALID about a Referenced Token can leak information to other parties. This document defines one additional Status Type with "SUSPENDED" that conveys such additional information, but in practice all statuses other than VALID and INVALID are likely to contain information with privacy implications.<a href="#section-12.8-1" class="pilcrow"></a></p>
2908-
<p id="section-12.8-2">A concrete example for "SUSPENDED" would be a driver's license, where the digital driver's license might still be useful to prove other information about its holder, but suspended could signal that it should not be considered valid in the scope of being allowed to drive a car. This case could be solved by either introducing a special status type, or by revoking the Referenced Token and re-issuing with changed attributes. For such a case, the status type suspended might be dangerous as it would leak the information of a suspended driver's license even if the driver's license is used as a mean of identification and not in the context of driving a car. This could also allow for the unwanted collection of statistical data on the status of driver's licenses.<a href="#section-12.8-2" class="pilcrow"></a></p>
2909-
<p id="section-12.8-3">Ecosystems that want to use other Status Types than "VALID" and "INVALID" should consider the possible leakage of data and profiling possibilities before doing so and evaluate if revocation and re-issuance might a better fit for their use-case.<a href="#section-12.8-3" class="pilcrow"></a></p>
2906+
<p id="section-12.8-2">Ecosystems that want to use other Status Types than "VALID" and "INVALID" should consider the possible leakage of data and profiling possibilities before doing so and evaluate if revocation and re-issuance might a better fit for their use-case.<a href="#section-12.8-2" class="pilcrow"></a></p>
29102907
</section>
29112908
</div>
29122909
</section>
@@ -4679,10 +4676,16 @@ <h2 id="name-document-history">
46794676
<p id="appendix-D-2">-14<a href="#appendix-D-2" class="pilcrow"></a></p>
46804677
<ul class="normal">
46814678
<li class="normal" id="appendix-D-3.1">
4682-
<p id="appendix-D-3.1.1">slightly restructure/clarify referenced token cose section<a href="#appendix-D-3.1.1" class="pilcrow"></a></p>
4679+
<p id="appendix-D-3.1.1">remove cose_sign1 tag from statuslist in cwt form examples<a href="#appendix-D-3.1.1" class="pilcrow"></a></p>
46834680
</li>
46844681
<li class="normal" id="appendix-D-3.2">
4685-
<p id="appendix-D-3.2.1">Add ASN.1 module<a href="#appendix-D-3.2.1" class="pilcrow"></a></p>
4682+
<p id="appendix-D-3.2.1">slightly restructure/clarify referenced token cose section<a href="#appendix-D-3.2.1" class="pilcrow"></a></p>
4683+
</li>
4684+
<li class="normal" id="appendix-D-3.3">
4685+
<p id="appendix-D-3.3.1">Add ASN.1 module<a href="#appendix-D-3.3.1" class="pilcrow"></a></p>
4686+
</li>
4687+
<li class="normal" id="appendix-D-3.4">
4688+
<p id="appendix-D-3.4.1">removed DL suspension example<a href="#appendix-D-3.4.1" class="pilcrow"></a></p>
46864689
</li>
46874690
</ul>
46884691
<p id="appendix-D-4">-13<a href="#appendix-D-4" class="pilcrow"></a></p>

0 commit comments

Comments
 (0)