-
Notifications
You must be signed in to change notification settings - Fork 7.9k
Labels
kind/enhancementCategorizes a PR related to an enhancementCategorizes a PR related to an enhancementrelease/26.4.2release/26.5.0
Milestone
Description
Description
SPIFFE/SPIRE can be configured to either expose the bundle endpoint or using the OIDC plugin. Neither are exposed by default.
The OIDC plugin exposes JWKS where the JWK does not have a use claim, while the bundle endpoint has use=jwt-svid. We should also support use=sig as that is frequently used by OIDC compliant vendors, and may be used by some SPIFFE implementations.
Value Proposition
Allow using a wider range of SPIFFE vendors without requiring specific configuration to use with Keycloak
Goals
- Support
use=sigand nouseclaim
Non-Goals
Discussion
No response
Notes
No response
Metadata
Metadata
Assignees
Labels
kind/enhancementCategorizes a PR related to an enhancementCategorizes a PR related to an enhancementrelease/26.4.2release/26.5.0