{"id":2560,"date":"2024-07-25T13:26:01","date_gmt":"2024-07-25T20:26:01","guid":{"rendered":"https:\/\/self-issued.info\/?p=2560"},"modified":"2024-07-25T13:26:01","modified_gmt":"2024-07-25T20:26:01","slug":"fourth-and-likely-last-implementers-draft-of-openid-federation-specification","status":"publish","type":"post","link":"https:\/\/self-issued.info\/?p=2560","title":{"rendered":"Fourth and Likely Last Implementer\u2019s Draft of OpenID Federation Specification"},"content":{"rendered":"<p><span class=\"plain\"><img decoding=\"async\" align=\"right\" alt=\"OpenID logo\" src=\"http:\/\/self-issued.info\/images\/openid-logo.png\"><\/span>The OpenID Foundation has <a href=\"https:\/\/openid.net\/fourth-implementers-draft-of-openid-federation-approved\/\">approved<\/a> the <a href=\"https:\/\/openid.net\/specs\/openid-federation-1_0-ID4.html\">Fourth Implementer\u2019s Draft of the OpenID Federation Specification<\/a>.  This is a major step towards having the specification become final.<\/p>\n<p>The <a href=\"https:\/\/openid.net\/specs\/openid-connect-federation-1_0-ID3.html\">previous Implementer\u2019s Draft<\/a> was in 2021.  A lot has happened since then, largely motivated by feedback from actual implementations and deployments.  Some highlights of progress made in the spec since then are:<\/p>\n<ul>\n<li>Changed name from OpenID Connect Federation to OpenID Federation, since Federation can be used for trust establishment for any protocol (including OpenID Connect).<\/li>\n<li>Introduced distinct Federation endpoints.<\/li>\n<li>Clearly defined and consistently used the terms Entity Statement, Entity Configuration, and Subordinate Statement.<\/li>\n<li>Clearly defined which claims can occur in which kinds of Entity Statements.<\/li>\n<li>Clearly defined Entity Types and the Federation Entity entity type.<\/li>\n<li>Enhanced description of Trust Mark issuance and usage.<\/li>\n<li>Defined relationship between metadata and metadata policy.<\/li>\n<li>Clearly defined interactions between policy operators.<\/li>\n<li>Defined where constraints may occur.<\/li>\n<li>Tightened descriptions of Automatic Registration and Explicit Registration.<\/li>\n<li>Added Historical Keys.<\/li>\n<li>Defined and used <code>trust_chain<\/code> JWS Header Parameter.<\/li>\n<li>Allowed Trust Chains to start with non-Trust Anchors.<\/li>\n<li>Clarified use of client authentication.<\/li>\n<li>Used OAuth Protected Resource Metadata.<\/li>\n<li>Consistent error handling.<\/li>\n<li>Added General-Purpose JWT Claims section.<\/li>\n<li>Comprehensive use of content types and media types.<\/li>\n<li>IANA registration of parameters, claims, and media types.<\/li>\n<li>Added and improved many diagrams.<\/li>\n<li>Substantial rewrites for increased consistency and clarity.<\/li>\n<li>Added <a href=\"https:\/\/www.linkedin.com\/in\/giuseppe-de-marco-bb054245\/\">Giuseppe De Marco<\/a> and <a href=\"https:\/\/www.linkedin.com\/in\/vladimirdzhuvinov\/\">Vladimir Dzhuvinov<\/a> as editors.<\/li>\n<\/ul>\n<p>As a preview of coming attractions, I&#8217;ll note that profiles of OpenID Federation are being written describing how it being used in wallet ecosystems and how it is being used in open finance ecosystems.  And we&#8217;re creating a list of implementations.  Watch this space for future announcements.<\/p>\n<p>Special thanks to all the implementers and deployers who provided feedback to get us to this point!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The OpenID Foundation has approved the Fourth Implementer\u2019s Draft of the OpenID Federation Specification. This is a major step towards having the specification become final. The previous Implementer\u2019s Draft was in 2021. A lot has happened since then, largely motivated by feedback from actual implementations and deployments. Some highlights of progress made in the spec [&hellip;]<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[8,7,26,14,25],"tags":[],"class_list":["post-2560","post","type-post","status-publish","format-standard","hentry","category-claims","category-federation","category-oauth","category-openid","category-specifications"],"_links":{"self":[{"href":"https:\/\/self-issued.info\/index.php?rest_route=\/wp\/v2\/posts\/2560","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/self-issued.info\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/self-issued.info\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/self-issued.info\/index.php?rest_route=\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/self-issued.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2560"}],"version-history":[{"count":4,"href":"https:\/\/self-issued.info\/index.php?rest_route=\/wp\/v2\/posts\/2560\/revisions"}],"predecessor-version":[{"id":2564,"href":"https:\/\/self-issued.info\/index.php?rest_route=\/wp\/v2\/posts\/2560\/revisions\/2564"}],"wp:attachment":[{"href":"https:\/\/self-issued.info\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2560"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/self-issued.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2560"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/self-issued.info\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2560"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}