ietf-wg-privacypass / draft-ietf-privacypass-consistency-mirror

K-Check protocol specification
Other
0 stars 5 forks source link

Support well-known resource declaring all valid keys #33

Open sysrqb opened 7 months ago

sysrqb commented 7 months ago

From the adoption call:

For Privacy Pass specifically, I think it is worth defining an OPTIONAL endpoint /.well-known/mirror-resource
that would allow clients to retrieve all issuer keys before discovering it when prompted by an Origin. A
similar endpoint is provided in Cloudflare attester implementation [2] for instance. This endpoint could be as
simple as a list:
GET /.well-known/mirror-resources
https://issuer1.example/.well-known/private-token-issuer-directory
https://issuer2.example/.well-known/private-token-issuer-directory