Required for hashing operations, used to compute JWK thumbprints when comparing key material across subordinate statements and entity configurations.
Required for verifying entity statement signatures.
OptionaltrustNon-empty list of trusted trust anchor URLs. When provided, the chain root must be one of them. When omitted, any chain root is accepted without binding to a known trust anchor — callers are responsible for applying their own root-of-trust verification in that case.
Required for chains with intermediate entities (chains longer than two elements). Used to fetch each intermediate issuer's entity configuration for self-signature verification.