Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

_aliases

Metadata

Description

Requirement

Defined in

Comment

issuer

MUST be a globally unique URL.
”Corresponds” to where the authorization server metadata is located.

REQUIRED
The issuer parameter value in the oauth_authorization_server metadata MUST match the Federation Entity Identifier (the iss Claim in the Entity Configuration)

[RFC8414], REQUIRED

[OpenID.Fed.OIDC]
REQUIRED



grant_types_supported

Supported Grant Types

OPTIONAL
The same requirements as specified in Section 2 of [RFC8414], with the following exception:

If the parameter is omitted, the default value SHALL be [ "authorization_code" ].

[RFC8414], OPTIONAL, ["authorization_code", "implicit"] is default if not present

Note: [Ena.OAuth]: If the parameter is omitted, the default value SHALL be "authorization_code"

Could it be a risk to change the default of the standard?

token_endpoint

Endpoint for requesting access tokens

REQUIRED

[RFC8414], REQUIRED


token_endpoint_auth_methods_supported

Client authentication methods supported by the token endpoint.

REQUIRED and MUST include private_key_jwt.

[RFC8414] OPTIONAL, client_secret_basic is default if not present

In line with the security requirements

token_endpoint_auth_signing_alg_values_supported

JWS signing algorithms for client authentication supported by the token endpoint.

REQUIRED
and MUST conform to the signature requirements (separately specified)

[RFC8414] REQUIRED when private_key_jwt is used.


scopes_supported

scopes supported by the authorization server

REQUIRED
SHOULD list all scopes supported by the authorization server

[RFC8414] , RECOMMENDED

[Ena.OAuth]
REQUIRED

What is the rationale for this sharper requirement in Ena.OAuth?

dpop_signing_alg_values_supported

JWS algorithms supported for DPoP proof JWTs.
Signals that the authorization server supports the DPoP mechanism.

RECOMMENDED

[Ena.OAuth]
RECOMMENDED
The use of DPoP is recommended to mitigate replay attacks.


authorization_response_iss_parameter_supported

indicates whether the authorization server supports including the issuer parameter in authorization responses to protect against Authorization Server Mix-Up Attacks

SHOULD

OPTIONAL?

[RFC9207]

[Ena.OAuth]
SHOULD be used and be set to true, for authorization servers within a federation

issuer is already required, so this could be OPTIONAL because this is only an indication?

jwks

The Entity's JSON Web Key Set, representing the Entity's protocol keys, included by value in the metadata.

REQUIRED if jwks_uri is not provided

[OpenID.Fed]

[Ena.OAuth], and [RFC8414]
does NOT include this.

Not supported?

jwks_uri

URL referencing a JWK Set document containing the Entity's protocol keys for that Entity Type

REQUIRED if jwks is not provided

[OpenID.Fed]
REQUIRED if jwks is not provided

[RFC8414]
OPTIONAL

[Ena.OAuth]
REQUIRED

[Ena.OAuth] has this as the only option - why?

signed_jwks_uri

URL referencing a signed JWT having the Entity's JWK Set document, representing the Entity's protocol keys for that Entity Type as its payload

OPTIONAL

[OpenID.Fed]

[Ena.OAuth], and [RFC8414]
does NOT include this.

Not supported?

Below is ONLY applicable IF the corresponding features are supported.

authorization_endpoint

URL of the authorization server's authorization endpoint

REQUIRED IF authorization code grant type is supported.

[RFC8414] REQUIRED
unless no grant types are supported that use the authorization endpoint

Out of cope for SIB BAS Step 1, but should be included.


code_challenge_methods_supported

PKCE [RFC7636] code challenge methods supported

REQUIRED IF authorization code grant type is supported.

[RFC8414] OPTIONAL

[Ena.OAuth]
REQUIRED for authorization code grant.


ui_locales_supported

Languages and scripts supported for the user interface

SHOULD
and should include Swedish (sv) and English (en).

[RFC8414] OPTIONAL

[Ena.OAuth] SHOULD.

Should only be relevant if the authorization endpoint is supported.

pushed_authorization_request_endpoint

URL of the authorization server's endpoint for pushed authorization requests

REQUIRED IF pushed authorization requests are supported.

Section 5 of [RFC9126] (extension)

[Ena.OAuth]
CONDITIONAL


protected_resources

resource identifiers for OAuth protected resources as defined Section 4 of [RFC9728]

OPTIONAL

[Ena.OAuth]
RECOMMENDED

An extension to RFC8414.

registration_endpoint

URL of the authorization server's OAuth 2.0 Dynamic Client Registration endpoint

OPTIONAL


[RFC8414] OPTIONAL


revocation_endpoint

URL of the authorization server's revocation endpoint

OPTIONAL

[RFC8414] OPTIONAL


revocation_endpoint_auth_methods_supported

client authentication methods supported by this revocation endpoint

OPTIONAL

[RFC8414] OPTIONAL


revocation_endpoint_auth_signing_alg_values_supported

signing algorithms supported by this endpoint for the signature on the JWT, when used with private_key_jwt

OPTIONAL

[RFC8414] OPTIONAL


introspection_endpoint

URL of the authorization server's introspection endpoint

OPTIONAL

[RFC8414] OPTIONAL


introspection_endpoint_auth_methods_supported

signing algorithms client authentication methods supported by this endpoint for the signature on the JWT, when used with private_key_jwt

OPTIONAL

[RFC8414] OPTIONALmtls


introspection_endpoint_auth_signing_alg_values_supported

signing algorithms supported by this endpoint for the signature on the JWT, when used with private_key_jwt

OPTIONAL

[RFC8414] OPTIONAL


mtls_endpoint_aliases


OPTIONAL

[

OPTIONAL

[Ena.OAuth]
SHOULD if Mutual TLS is supported for client authentication.


tls_client_certificate_bound_access_tokens

indicates authorization server support for mutual TLS client certificate-bound access tokens

OPTIONAL

Section 3.3 of [RFC8705]

[RFC8705] Mutual-TLS client certificate-Bound Access Tokens does not combine well with private_key_jwt.

require_signed_request_object

indicates where whether authorization request needs to be protected as Request Object and provided through either request or request_uri parameter

OPTIONAL

Section 10.5 of [RFC9101]

[Ena.OAuth]
Section 3.1.1.10 and
Section 7.2, JAR – JWT-Secured Authorization Requests.

...


require_pushed_authorization_requests

Boolean parameter indicating whether the authorization server accepts authorization request data only via PAR. If omitted, the default value is false.

OPTIONAL

Section 5 of [RFC9126].

Section ??? of 
[Ena.OAuth]


pushed_authorization_request_endpoint

The URL of the pushed authorization request endpoint at which a client can post an authorization request to exchange for a request_uri value usable at the authorization server

OPTIONAL

Section 5 of [RFC9126].

Section 3.1.1.2 of [Ena.OAuth]



 
 
 

OpenID Relying Party (RP) metadata requirements


 
 

OpenID Relying Party (RP) metadata requirements

...

Metadata

Description

Requirement

Defined in

Comment

redirect_uris

Array of redirection URI values used by the Relying Party.

REQUIRED

[RFC7591] REQUIRED
[OIDC.Sweden] REQUIRED

response_types

The response types that the Relying Party uses. Must be set to code.

REQUIRED

[RFC7591] OPTIONAL

[OIDC.Sweden] REQUIRED

grant_types

The OAuth2 grant types the Relying Party uses.

REQUIRED
MUST be set to authorization_code.

[RFC7591] OPTIONAL

Metadata

Description

Requirement

Defined in

Comment

redirect_uris

Array of redirection URI values used by the Relying Party.

REQUIRED

[RFC7591] REQUIRED


[OIDC.Sweden] REQUIRED

token_endpoint_auth_method

Authentication method for accessing the Token endpoint.


response_types

The response types that the Relying Party uses. Must be set to code.

REQUIRED

REQUIRED
MUST be set to private_key_jwt

[RFC7591] OPTIONAL


default is client_secret_basic

[OIDC.Sweden] REQUIRED

jwks

The Entity's JSON Web Key Set, representing the Entity's protocol keys, included by value in the metadata.

REQUIRED IF jwks_uri is not provided

[OpenID.Fed]

[RFC7591] OPTIONAL

[RFC7591] The jwks_uri and jwks parameters MUST NOT be used together.

jwks_uri

URL referencing a JWK Set document containing the Entity's protocol keys for that Entity Type

REQUIRED IF jwks is not provided



grant_types

The OAuth2 grant types the Relying Party uses.

REQUIRED
MUST be set to authorization_code.

[RFC7591] OPTIONAL

[OIDC.Sweden] REQUIRED


token_endpoint_auth_method

Authentication method for accessing the Token endpoint.

REQUIRED
MUST be set to private_key_jwt

[OpenID.Fed]

[RFC7591] OPTIONAL

[RFC7591] The jwks_uri and jwks parameters MUST NOT be used together.

default is client_secret_basic

[OIDC.Sweden] REQUIRED


jwks

The Entity's JSON Web Key Set

signed_jwks_uri

URL referencing a signed JWT having the Entity's JWK Set document

, representing the Entity's protocol keys

for that Entity Type as its payloadOPTIONAL

, included by value in the metadata.

REQUIRED IF jwks_uri is not provided

[OpenID.Fed]

default_acr_values

Default requested Authentication Context Class Reference values.

OPTIONAL

[RFC7591] OPTIONAL

[OIDC.Sweden] OPTIONAL

subject_type

Subject type requested for responses to this Client.

OPTIONAL

[RFC7591] OPTIONAL

[OIDC.Sweden] OPTIONAL

...

[RFC7591] OPTIONAL

[RFC7591] The jwks_uri and jwks parameters MUST NOT be used together.

jwks_uri

URL referencing a JWK Set document containing the Entity's protocol keys for that Entity Type

REQUIRED IF jwks is not provided

[OpenID.Fed]

[RFC7591] OPTIONAL

[RFC7591] The jwks_uri and jwks parameters MUST NOT be used together.

signed_jwks_uri

URL referencing a signed JWT having the Entity's JWK Set document, representing the Entity's protocol keys for that Entity Type as its payload

OPTIONAL

[OpenID.Fed]


default_acr_values

Default requested Authentication Context Class Reference values.

OPTIONAL

[RFC7591] OPTIONAL

[OIDC.Sweden] OPTIONAL


subject_type

Subject type requested for responses to this Client.

OPTIONAL

[RFC7591] OPTIONAL

[OIDC.Sweden] OPTIONAL


client_registration_types

the client registration types the RP supports. Values defined by this specification are automatic and explicit. Additional values MAY be defined and used, without restriction by this specification

RECOMMENDED?

[OpenID.Fed.OIDC]
RECOMMENDED 




 
 

OpenID Provider metadata requirements 

Metadata

Description

Requirement

Defined in

Comment

issuer

The Issuer Identifier of the OpenID Provider. The value MUST match the Entity Identifier of the OpenID Provider, that is, the iss Claim of its Entity Configuration, see Section 5.1.3 of [OpenID.Fed].

REQUIRED

[OIDC.Discovery] 

[OpenID.Fed.OIDC]


authorization_endpoint

The URL of the OpenID Provider's authorization endpoint.

REQUIRED

[OIDC.Discovery] REQUIRED


token_endpoint

 

REQUIRED

[OIDC.Discovery]


userinfo_endpoint

URL of the OP's OAuth 2.0 Token Endpoint 

RECOMMENDED

[OIDC.Discovery] RECOMMENDED


registration_endpoint

URL of the OP's Dynamic Client Registration Endpoint 

RECOMMENDED

[OIDC.Discovery] RECOMMENDED


scopes_supported

The scope values the OpenID Provider supports. 

RECOMMENDED

[OIDC.Discovery] RECOMMENDED


response_types_supported

list of the OAuth 2.0 response_type values that this OP supports

REQUIRED
The value MUST contain code, see Section 5.2 of [OIDC.Sweden].

[OIDC.Discovery] REQUIRED


grant_types_supported

 


 


acr_values_supported

list of the Authentication Context Class References that this OP supports.


 


 

 


 


client_registration_types_supported

the client registration types the OP supports. Values defined by this specification are automatic and explicit. Additional values MAY be defined and used, without restriction by this specification

RECOMMENDED?

[OpenID.Fed.OIDC]
RECOMMENDED 


federation_registration_endpoint

URL of the OP's federation-specific Dynamic Client Registration Endpoint

OPTIONAL

If the OP supports Explicit Client Registration Endpoint this URL MUST use the https scheme and MAY contain port, path, and query parameter components; it MUST NOT contain a fragment component. If the OP supports Explicit Client Registration as described in Section 12.2, then this Claim is REQUIRED

[OpenID.Fed.OIDC] OPTIONAL







 





jwks_uri



[OIDC.Discovery] REQUIRED


 





 





 

OpenID Provider metadata requirements 

Metadata

Description

Requirement

Defined in

Comment

TBD





https://id.oidc.se/disco/authnProviderSupported

indicates whether the request extension parameter https://id.oidc.se/param/authnProvider is supported

OPTIONAL

[OIDC.Sweden.Parameters]

[Ena.OAuth]
RECOMMENDED for servers that support multiple authentication methods
Authorization servers that do support the parameter MUST indicate this in their metadata. See Section 5.1.1.1, Extension Parameter for Controlling User Authentication at the Authorization Server.







TBD










Appendix

Organization identifier formats

...

[OpenID.Fed.Reg.Policy] https://www.oidc.se/openid-federation-registration-policy/main.html

[OpenID.Fed.OIDC] https://openid.net/specs/openid-federation-connect-1_1.html

[RFC7591] https://openid.net/specs/openid-connect-registration-1_0.html

[OIDC.Sweden] https://www.oidc.se/specifications/

[OIDC.Discovery] https://openid.net/specs/openid-connect-discovery-1_0.html

Notes

  • [OpenID.Fed.Swe.Profile] contains recommendations regarding “Adapting OAuth 2.0 and OpenID Connect for OpenID Federation“, chapter 7, which may affect metadata requirements:

    • “For federation deployments based on this profile, it is RECOMMENDED that support for the parameters defined in [OpenID.RP.Choices] be mandatory for federation participants.“

    • “It is RECOMMENDED that the Federation Operator define requirements for which client authentication methods OAuth 2.0 Authorization Servers and OpenID Connect OpenID Providers should support, in order to avoid such interoperability problems.“

    • “Requirements for OpenID Connect Subject Types

      Section 2 of [OpenID.Registration] defines the subject_type metadata parameter, which is used by an OpenID Connect Relying Party to declare whether it requires subject identifiers in tokens to be public or pairwise. Correspondingly, an OpenID Provider's Discovery metadata contains the subject_types_supported parameter [OpenID.Discovery], listing the subject types the OpenID Provider supports. If OpenID Providers within the federation do not support both types, interoperability issues may arise. It is RECOMMENDED that the Federation Operator, via referenced profiles or federation rules, require OpenID Providers to support both the public and pairwise subject types.”