oidc-sweden / specifications

Specifications for the Swedish OpenID Connect profile
13 stars 0 forks source link

IS-82 Signing requirements #87

Closed martin-lindstrom closed 11 months ago

martin-lindstrom commented 11 months ago

In order to have a better way of detecting which key the sender used, the use of kid in JOSE headers are set to SHOULD (also in cases where the entity's JWK set only contains one signing key). The reason is mainly to enable dynamic re-load of JWKS-documents after key rollover.

Closes #82