You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
If not further specified, the term Issuer may refer to an entity acting for all three roles.
This sentence should be removed.
The role of the Issuer and of the Status Issuer should be kept separate in the whole document.
A Status Issuer does not have access to the data that has been provided when the user was enrolled by the Issuer.
As a consequence, the following sentence should be reconsidered:
If the roles of the Issuer and the Status Provider are performed by
two different entities, this may give additional privacy assurances
as the Issuer has no means to identify the Relying Party or its
request.
These "additional privacy assurances" exist as soon as the role of the Issuer and of the Status Issuer are kept separate.
The text was updated successfully, but these errors were encountered:
See the issue #227 "Which keys should be used to sign and verify Status List Tokens ?" which contains more details.
If the same key is used to sign the Referenced Token and the Token Status List, then the term Issuer may refer to an entity acting for all three roles.
If the Issuer and the Status Issuer use different keys, then the role of the entity signing Referenced Tokens should not be confused with the role of the entity signing Token Status Lists.
On page 3, the text states:
This sentence should be removed.
The role of the Issuer and of the Status Issuer should be kept separate in the whole document.
A Status Issuer does not have access to the data that has been provided when the user was enrolled by the Issuer.
As a consequence, the following sentence should be reconsidered:
These "additional privacy assurances" exist as soon as the role of the Issuer and of the Status Issuer are kept separate.
The text was updated successfully, but these errors were encountered: