Skip to content

Allow external JWT issuers, following the OAuth2.0/OIDC spec #34

Description

@wistefan

Is your feature request related to a problem? Please describe.
All tokens used for authenticating users or participants are currently signed by the consent-manager itself. This prevents the consent-manager to be integrated with external IDPs(like Keycloak) or authentication flows using OID4VC(integrating with the EUDI Wallet ARF).

Describe the solution you'd like
The consent-manager should be able to trust external IDPs, following the OIDC spec. For configured issuers, the consent-manager will resolve public keys by following the ODIC/Oauth2.0 discovery, e.g. .well-known/openid-configuration and its jwks endpoint. Incoming JWTs will be verified against those keys.

Following that solution, users could f.e. identify themself using a EUDI Wallet ARF PID or participants could identify using Verifiable Credentials like the Gaia-X Participant Credential

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions