Fabio Martelli created SYNCOPE-1936:
---------------------------------------

             Summary: Cannot be generated JWKS with enc key inside
                 Key: SYNCOPE-1936
                 URL: https://issues.apache.org/jira/browse/SYNCOPE-1936
             Project: Syncope
          Issue Type: Improvement
          Components: core, wa
    Affects Versions: 4.0.3, 3.0.15
            Reporter: Fabio Martelli
             Fix For: 3.0.16, 4.0.4


JWKS with key to be used for encryption canno be generated.

The expected use of the keys to be genrerated cannot be specified so a single 
signing key is provided and added to the JWKS.

You can find confirmation by looking into OIDCJWKSDataBinderImpl where just 
KeyUse.SIGNATURE is handled.

This is a big problem for WA that currently cannot encrypt JWTs by limiting, 
consequently, some functions like as OIDC.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to