Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

jwks description of what Federation Entity Keys are used for is misleading #89

Closed
selfissued opened this issue Sep 12, 2024 · 0 comments · Fixed by #97
Closed

jwks description of what Federation Entity Keys are used for is misleading #89

selfissued opened this issue Sep 12, 2024 · 0 comments · Fixed by #97
Assignees

Comments

@selfissued
Copy link
Member

The jwks description at https://openid.net/specs/openid-federation-1_0-ID4.html#name-entity-statement says:

The public keys are used to verify the signatures of the issued Entity Statements and Trust Marks and SHOULD NOT be used in other protocols.

As @peppelinux wrote about this "we have also resolve response, historical keys response and so on. All about trust uses the federation entity keys".

We need to correct this description so readers don't think that Entity Statements and Trust Marks are the only things that Federation Entity Keys are used for.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant