[Openid-specs-mobile-profile] Issue 52 CIBA Pairwise Identifiers Structuring Text

Axel.Nennker at telekom.de Axel.Nennker at telekom.de
Wed Jun 14 07:52:19 UTC 2017


From: Manger, James [mailto:James.H.Manger at team.telstra.com]
Sent: Mittwoch, 14. Juni 2017 06:29
To: Nennker, Axel <Axel.Nennker at telekom.de>; ve7jtb at ve7jtb.com
Cc: openid-specs-mobile-profile at lists.openid.net
Subject: RE: [Openid-specs-mobile-profile] Issue 52 CIBA Pairwise Identifiers Structuring Text


> What are the threats if all client metadata is validated at registration time and all CIBA requests are authenticated?

-          BadClient is not able to register for the same sector_identifier_uri as GoodPollingClient (regardless of CIBA or OIDC) This is nothing bad introduced by CIBA.

This is your mistake.
Multiple clients can register the same sector_identifier_uri — that is the whole point of the sector_id concept (grouping multiple apps). The issue is how does the registration system distinguish BadClient from OtherGoodPollingClient when both register the same sector_id?
I understand that point. That is the whole purpose of sector_identifier_uri.
The current Discovery spec does not go into details on validation.
The OIDC spec, too, does not go into detail how the validation is done.
There is nothing that is CIBA specific about validation.

James Manger

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openid.net/pipermail/openid-specs-mobile-profile/attachments/20170614/32514524/attachment-0001.html>

More information about the Openid-specs-mobile-profile mailing list