You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
<pid="section-5.1-5.2.1"><code>iat</code>: <spanclass="bcp14">REQUIRED</span>. As generally defined in <span>[<ahref="#RFC7519" class="cite xref">RFC7519</a>]</span>. The <code>iat</code> (issued at) claim <spanclass="bcp14">MUST</span> specify the time at which the Status List Token was issued.<ahref="#section-5.1-5.2.1" class="pilcrow">¶</a></p>
1881
1881
</li>
1882
1882
<liclass="normal" id="section-5.1-5.3">
1883
-
<pid="section-5.1-5.3.1"><code>exp</code>: <spanclass="bcp14">OPTIONAL</span>. As generally defined in <span>[<ahref="#RFC7519" class="cite xref">RFC7519</a>]</span>. The <code>exp</code> (expiration time) claim, if present, <spanclass="bcp14">MUST</span> specify the time at which the Status List Token is considered expired by the Status Issuer. Consider the guidance provided in <ahref="#expiry-and-caching" class="auto internal xref">Section 13.7</a>.<ahref="#section-5.1-5.3.1" class="pilcrow">¶</a></p>
1883
+
<pid="section-5.1-5.3.1"><code>exp</code>: <spanclass="bcp14">RECOMMENDED</span>. As generally defined in <span>[<ahref="#RFC7519" class="cite xref">RFC7519</a>]</span>. The <code>exp</code> (expiration time) claim, if present, <spanclass="bcp14">MUST</span> specify the time at which the Status List Token is considered expired by the Status Issuer. Consider the guidance provided in <ahref="#expiry-and-caching" class="auto internal xref">Section 13.7</a>.<ahref="#section-5.1-5.3.1" class="pilcrow">¶</a></p>
1884
1884
</li>
1885
1885
<liclass="normal" id="section-5.1-5.4">
1886
-
<pid="section-5.1-5.4.1"><code>ttl</code>: <spanclass="bcp14">OPTIONAL</span>. The <code>ttl</code> (time to live) claim, if present, <spanclass="bcp14">MUST</span> specify the maximum amount of time, in seconds, that the Status List Token can be cached by a consumer before a fresh copy <spanclass="bcp14">SHOULD</span> be retrieved. The value of the claim <spanclass="bcp14">MUST</span> be a positive number encoded in JSON as a number. Consider the guidance provided in <ahref="#expiry-and-caching" class="auto internal xref">Section 13.7</a>.<ahref="#section-5.1-5.4.1" class="pilcrow">¶</a></p>
1886
+
<pid="section-5.1-5.4.1"><code>ttl</code>: <spanclass="bcp14">RECOMMENDED</span>. The <code>ttl</code> (time to live) claim, if present, <spanclass="bcp14">MUST</span> specify the maximum amount of time, in seconds, that the Status List Token can be cached by a consumer before a fresh copy <spanclass="bcp14">SHOULD</span> be retrieved. The value of the claim <spanclass="bcp14">MUST</span> be a positive number encoded in JSON as a number. Consider the guidance provided in <ahref="#expiry-and-caching" class="auto internal xref">Section 13.7</a>.<ahref="#section-5.1-5.4.1" class="pilcrow">¶</a></p>
1887
1887
</li>
1888
1888
<liclass="normal" id="section-5.1-5.5">
1889
1889
<pid="section-5.1-5.5.1"><code>status_list</code>: <spanclass="bcp14">REQUIRED</span>. The <code>status_list</code> (status list) claim <spanclass="bcp14">MUST</span> specify the Status List conforming to the structure defined in <ahref="#status-list-json" class="auto internal xref">Section 4.2</a>.<ahref="#section-5.1-5.5.1" class="pilcrow">¶</a></p>
<pid="section-5.2-5.2.1"><code>6</code> (issued at): <spanclass="bcp14">REQUIRED</span>. As generally defined in <span>[<ahref="#RFC8392" class="cite xref">RFC8392</a>]</span>. The issued at claim <spanclass="bcp14">MUST</span> specify the time at which the Status List Token was issued.<ahref="#section-5.2-5.2.1" class="pilcrow">¶</a></p>
1949
1949
</li>
1950
1950
<liclass="normal" id="section-5.2-5.3">
1951
-
<pid="section-5.2-5.3.1"><code>4</code> (expiration time): <spanclass="bcp14">OPTIONAL</span>. As generally defined in <span>[<ahref="#RFC8392" class="cite xref">RFC8392</a>]</span>. The expiration time claim, if present, <spanclass="bcp14">MUST</span> specify the time at which the Status List Token is considered expired by its issuer. Consider the guidance provided in <ahref="#expiry-and-caching" class="auto internal xref">Section 13.7</a>.<ahref="#section-5.2-5.3.1" class="pilcrow">¶</a></p>
1951
+
<pid="section-5.2-5.3.1"><code>4</code> (expiration time): <spanclass="bcp14">RECOMMENDED</span>. As generally defined in <span>[<ahref="#RFC8392" class="cite xref">RFC8392</a>]</span>. The expiration time claim, if present, <spanclass="bcp14">MUST</span> specify the time at which the Status List Token is considered expired by its issuer. Consider the guidance provided in <ahref="#expiry-and-caching" class="auto internal xref">Section 13.7</a>.<ahref="#section-5.2-5.3.1" class="pilcrow">¶</a></p>
1952
1952
</li>
1953
1953
<liclass="normal" id="section-5.2-5.4">
1954
-
<pid="section-5.2-5.4.1"><code>65534</code> (time to live): <spanclass="bcp14">OPTIONAL</span>. Unsigned integer (Major Type 0). The time to live claim, if present, <spanclass="bcp14">MUST</span> specify the maximum amount of time, in seconds, that the Status List Token can be cached by a consumer before a fresh copy <spanclass="bcp14">SHOULD</span> be retrieved. The value of the claim <spanclass="bcp14">MUST</span> be a positive number. Consider the guidance provided in <ahref="#expiry-and-caching" class="auto internal xref">Section 13.7</a>.<ahref="#section-5.2-5.4.1" class="pilcrow">¶</a></p>
1954
+
<pid="section-5.2-5.4.1"><code>65534</code> (time to live): <spanclass="bcp14">RECOMMENDED</span>. Unsigned integer (Major Type 0). The time to live claim, if present, <spanclass="bcp14">MUST</span> specify the maximum amount of time, in seconds, that the Status List Token can be cached by a consumer before a fresh copy <spanclass="bcp14">SHOULD</span> be retrieved. The value of the claim <spanclass="bcp14">MUST</span> be a positive number. Consider the guidance provided in <ahref="#expiry-and-caching" class="auto internal xref">Section 13.7</a>.<ahref="#section-5.2-5.4.1" class="pilcrow">¶</a></p>
1955
1955
</li>
1956
1956
<liclass="normal" id="section-5.2-5.5">
1957
1957
<pid="section-5.2-5.5.1"><code>65533</code> (status list): <spanclass="bcp14">REQUIRED</span>. The status list claim <spanclass="bcp14">MUST</span> specify the Status List conforming to the structure defined in <ahref="#status-list-cbor" class="auto internal xref">Section 4.3</a>.<ahref="#section-5.2-5.5.1" class="pilcrow">¶</a></p>
<pid="section-6.3-9">ISO mdoc <span>[<ahref="#ISO.mdoc" class="cite xref">ISO.mdoc</a>]</span> may utilize the Status List mechanism by introducing the <code>status</code> parameter in the Mobile Security Object (MSO) as specified in Section 9.1.2. The <code>status</code> parameter uses the same encoding as a CWT as defined in <ahref="#referenced-token-cose" class="auto internal xref">Section 6.3</a>.<ahref="#section-6.3-9" class="pilcrow">¶</a></p>
<pid="appendix-D-2.1.1">Add short security consideraiton on redirects and ttl<ahref="#appendix-D-2.1.1" class="pilcrow">¶</a></p>
4592
+
<pid="appendix-D-2.1.1">Make exp and ttl recommended in claim description (fixes inconsistency, was recommended in other text)<ahref="#appendix-D-2.1.1" class="pilcrow">¶</a></p>
4593
4593
</li>
4594
4594
<liclass="normal" id="appendix-D-2.2">
4595
-
<pid="appendix-D-2.2.1">fix CORS spec to specific version<ahref="#appendix-D-2.2.1" class="pilcrow">¶</a></p>
4595
+
<pid="appendix-D-2.2.1">Add short security consideraiton on redirects and ttl<ahref="#appendix-D-2.2.1" class="pilcrow">¶</a></p>
<pid="appendix-D-2.3.1">fix CORS spec to specific version<ahref="#appendix-D-2.3.1" class="pilcrow">¶</a></p>
4599
4599
</li>
4600
4600
<liclass="normal" id="appendix-D-2.4">
4601
-
<pid="appendix-D-2.4.1">link implementation guidance to exp and ttl in Status List Token definition<ahref="#appendix-D-2.4.1" class="pilcrow">¶</a></p>
<pid="appendix-D-2.5.1">reference RFC7515 instead of IANA:JOSE<ahref="#appendix-D-2.5.1" class="pilcrow">¶</a></p>
4604
+
<pid="appendix-D-2.5.1">link implementation guidance to exp and ttl in Status List Token definition<ahref="#appendix-D-2.5.1" class="pilcrow">¶</a></p>
4605
4605
</li>
4606
4606
<liclass="normal" id="appendix-D-2.6">
4607
-
<pid="appendix-D-2.6.1">add a note that cwt is encoded in raw/binary.<ahref="#appendix-D-2.6.1" class="pilcrow">¶</a></p>
4607
+
<pid="appendix-D-2.6.1">reference RFC7515 instead of IANA:JOSE<ahref="#appendix-D-2.6.1" class="pilcrow">¶</a></p>
4608
4608
</li>
4609
4609
<liclass="normal" id="appendix-D-2.7">
4610
-
<pid="appendix-D-2.7.1">added further privacy consideration around issuer tracking using unique URIs<ahref="#appendix-D-2.7.1" class="pilcrow">¶</a></p>
4610
+
<pid="appendix-D-2.7.1">add a note that cwt is encoded in raw/binary.<ahref="#appendix-D-2.7.1" class="pilcrow">¶</a></p>
4611
+
</li>
4612
+
<liclass="normal" id="appendix-D-2.8">
4613
+
<pid="appendix-D-2.8.1">added further privacy consideration around issuer tracking using unique URIs<ahref="#appendix-D-2.8.1" class="pilcrow">¶</a></p>
0 commit comments