You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
<pid="section-6.3-9">ISO mdoc <span>[<ahref="#ISO.mdoc" class="cite xref">ISO.mdoc</a>]</span> may utilize the Status List mechanism by introducing the <code>status</code> parameter in the Mobile Security Object (MSO) as specified in Section 9.1.2. The <code>status</code> parameter uses the same encoding as a CWT as defined in <ahref="#referenced-token-cose" class="auto internal xref">Section 6.3</a>.<ahref="#section-6.3-9" class="pilcrow">¶</a></p>
<pid="section-8.1-1">To obtain the Status List Token, the Relying Party <spanclass="bcp14">MUST</span> send an HTTP GET request to the URI provided in the Referenced Token.<ahref="#section-8.1-1" class="pilcrow">¶</a></p>
2364
2364
<pid="section-8.1-2">The HTTP endpoint <spanclass="bcp14">SHOULD</span> support the use of Cross-Origin Resource Sharing (CORS) <span>[<ahref="#CORS" class="cite xref">CORS</a>]</span> and/or other methods as appropriate to enable Browser-based clients to access it, unless ecosystems using this specification choose not to support Browser-based clients.<ahref="#section-8.1-2" class="pilcrow">¶</a></p>
2365
-
<pid="section-8.1-3">The Relying Party <spanclass="bcp14">MUST</span> send the following Accept-Header to indicate the requested response type:<ahref="#section-8.1-3" class="pilcrow">¶</a></p>
2365
+
<pid="section-8.1-3">The Relying Party <spanclass="bcp14">SHOULD</span> send the following Accept HTTP Header to indicate the requested response type unless the Content-Type of Status List Tokens in the respective ecosystem is known or the Relying Party supports both formats:<ahref="#section-8.1-3" class="pilcrow">¶</a></p>
2366
2366
<ulclass="normal">
2367
2367
<liclass="normal" id="section-8.1-4.1">
2368
2368
<pid="section-8.1-4.1.1">"application/statuslist+jwt" for Status List Token in JWT format<ahref="#section-8.1-4.1.1" class="pilcrow">¶</a></p>
<pid="section-10-1"><span>[<ahref="#RFC5280" class="cite xref">RFC5280</a>]</span> specifies the Extended Key Usage (EKU) X.509 certificate extension for use on end entity certificates. The extension indicates one or more purposes for which the certified public key is valid. The EKU extension can be used in conjunction with the Key Usage (KU) extension, which indicates the set of basic cryptographic operations for which the certified key may be used. A certificate's issuer explicitly delegates Status List Token signing authority by issuing a X.509 certificate containing the KeyPurposeId defined below in the extended key usage extension.<ahref="#section-10-1" class="pilcrow">¶</a></p>
2596
+
<pid="section-10-1"><span>[<ahref="#RFC5280" class="cite xref">RFC5280</a>]</span> specifies the Extended Key Usage (EKU) X.509 certificate extension for use on end entity certificates. The extension indicates one or more purposes for which the certified public key is valid. The EKU extension can be used in conjunction with the Key Usage (KU) extension, which indicates the set of basic cryptographic operations for which the certified key may be used. A certificate's issuer explicitly delegates Status List Token signing authority by issuing a X.509 certificate containing the KeyPurposeId defined below in the extended key usage extension.
2597
+
Other specifications <spanclass="bcp14">MAY</span> choose to re-use this OID for other status mechanisms under the condition that they are registered in the "JWT Status Mechanisms" or "CWT Status Mechanisms" registries.<ahref="#section-10-1" class="pilcrow">¶</a></p>
2597
2598
<pid="section-10-2">The following OID is defined for usage in the EKU extension<ahref="#section-10-2" class="pilcrow">¶</a></p>
0 commit comments