Skip to content

Add section about supported algorithms for OpenID Connect #238

@martin-lindstrom

Description

@martin-lindstrom

In OpenID Connect Profile for Sweden Connect we rely on the cryptographic requirements stated in The Swedish OpenID Connect Profile.

The required signature algorithms according to this specification is only RS256 and ES256. We may want to extend the requirements for an OP to support a wider range of algorithms.

Also, if a client registers metadata in a federation, and it can freely set, for example, id_token_signed_response_alg, we run into problems. That would mean that an OP would need to use several different signing keys, one for each mandatory type. This needs to be addressed.

Metadata

Metadata

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions