[Openid-specs-ab] JSON Web Token (JWT) and JSON Web Signature (JWS) now in separate specs
Michael.Jones at microsoft.com
Sat Mar 26 05:25:36 UTC 2011
As promised, I have split the contents of the JWT spec draft-jones-json-web-token-01<http://self-issued.info/docs/draft-jones-json-web-token-01.html> into two simpler specs:
These should have introduced no semantic changes from the previous spec.
I then applied the feedback that I received since JWT -01 and created revised versions of the split specs:
The only breaking change introduced was that x5t (X.509 Certificate Thumbprint) is now a SHA-1 hash of the DER-encoded certificate, rather than a SHA-256 has, as SHA-1 is the prevailing existing practice for certificate thumbprint calculations. See the Document History sections for details on each change made.
.txt and .xml versions are also available. I plan to publish these as IETF drafts once the submission window re-opens on Monday. Feedback welcome!
P.S. Yes, work on the companion encryption spec is now under way...
-------------- next part --------------
An HTML attachment was scrubbed...
More information about the Openid-specs-ab