-
I'm following this guide #114 and have a question about this section:
What does that mean when you're both the issuer and recipient? Thanks in advance! |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment
-
That means when I both produce and consume the tokens. I issue them for my own later use.
Because you achieve all of Confidentiality, Integrity, and Authenticity with a direct or KW symmetric encryption. So, if you intend to encrypt a JWS that you both produce and consume, you may skip signing it with HMAC and simply encrypt it with your secret. |
Beta Was this translation helpful? Give feedback.
That means when I both produce and consume the tokens. I issue them for my own later use.
Because you achieve all of Confidentiality, Integrity, and Authenticity with a direct or KW symmetric encryption. So, if you intend to encrypt a JWS that you both produce and consume, you may skip signing it with HMAC and simply encrypt it with your secret.