Skip to content

User agent request validation and errors #472

@marcoscaceres

Description

@marcoscaceres

The prepare steps originally stated that:

In addition to protocol-defined requirements, a [=user agent=] might apply additional validation criteria based on local policy, configuration, or evolving security considerations. For example, a [=user agent=] might reject a request that (a) seeks particular credential attributes, (b) uses or requires cryptographic algorithms the [=user agent=] is configured not to accept (e.g., as part of algorithm agility or a transition to post-quantum schemes), or (c) relies on certificates or trust anchors that are not accepted by the [=user agent=]'s configured trust decisions.

It would be good to expand on these.

Metadata

Metadata

Assignees

Labels

specsubstantivePR adds normative/implementable requirements — triggers implementation bug filing on merge

Type

No type
No fields configured for issues without a type.

Projects

Status
In Progress

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions