-
Notifications
You must be signed in to change notification settings - Fork 0
Open
Description
From spec:
Certificates
X.509 certificates can be used by issuers to indicate the issuer's participation in a PKI-based trust framework.If the Verifier supports PKI-based trust frameworks and the Health Card issuer includes the "x5c" parameter in matching JWK entries from the .keys[] array, the Verifier establishes that the issuer is trusted as follows:
- Verifier validates the leaf certificate's binding to the Health Card issuer by:
- matching the <> to the value of a uniformResourceIdentifier entry in the certificate's Subject Alternative Name extension (see RFC5280), and
- verifying the signature in the Health Card using the public key in the certificate.
- Verifier constructs a valid certificate path of unexpired and unrevoked certificates to one of its trusted anchors (see RFC5280).
Metadata
Metadata
Assignees
Labels
No labels