Is your feature request related to a problem? Please describe.
All tokens used for authenticating users or participants are currently signed by the consent-manager itself. This prevents the consent-manager to be integrated with external IDPs(like Keycloak) or authentication flows using OID4VC(integrating with the EUDI Wallet ARF).
Describe the solution you'd like
The consent-manager should be able to trust external IDPs, following the OIDC spec. For configured issuers, the consent-manager will resolve public keys by following the ODIC/Oauth2.0 discovery, e.g. .well-known/openid-configuration and its jwks endpoint. Incoming JWTs will be verified against those keys.
Following that solution, users could f.e. identify themself using a EUDI Wallet ARF PID or participants could identify using Verifiable Credentials like the Gaia-X Participant Credential
Is your feature request related to a problem? Please describe.
All tokens used for authenticating users or participants are currently signed by the consent-manager itself. This prevents the consent-manager to be integrated with external IDPs(like Keycloak) or authentication flows using OID4VC(integrating with the EUDI Wallet ARF).
Describe the solution you'd like
The consent-manager should be able to trust external IDPs, following the OIDC spec. For configured issuers, the consent-manager will resolve public keys by following the ODIC/Oauth2.0 discovery, e.g. .well-known/openid-configuration and its jwks endpoint. Incoming JWTs will be verified against those keys.
Following that solution, users could f.e. identify themself using a EUDI Wallet ARF PID or participants could identify using Verifiable Credentials like the Gaia-X Participant Credential