ehealthsuisse / ch-epr-fhir

Repository for the swiss implementation guide for the FHIR based profiles
3 stars 5 forks source link

JWS in IUA #100

Closed msmock closed 6 months ago

msmock commented 6 months ago

Security Consideration: "As specified in the IUA profile, the IUA Authorization Client and Authorization Server actors SHALL support the JWS (signed) alternative of the JWT token." Does that mean actions shall use JWS, or only support them? It is also unclear in IUA because they say "JWT token shall be signed as specified in JSON Web Signature [RFC7515]. If signed,[...]".