-
Notifications
You must be signed in to change notification settings - Fork 15
Open
Description
From https://openid.net/specs/openid-connect-core-1_0.html#RotateSigKeys:
The signer can begin using a new key at its discretion and signals the change to the verifier using the
kidvalue. The verifier knows to go back to thejwks_urilocation to re-retrieve the keys when it sees an unfamiliarkidvalue.
IdPs may add a public key to JWKS and use the corresponding private key right away to sign JWT.
Couper will currently not recognize this change (until it syncs JWKS) and throw an error, because it can't find a key for the new kid in its cached JWKS.
So instead of throwing an error, Couper should first sync JWKS, then try again to find the key.
This may also apply to the jwt access control.
Metadata
Metadata
Assignees
Labels
No labels