Skip to content

Conversation

@stianst
Copy link
Contributor

@stianst stianst commented Oct 14, 2025

Simplifies look-up of the IdP by using the alias configured in the client. For SPIFFE this results in ignoring the iss claim, which is what we want as we don't know what the value should be, nor do we care, so we shouldn't require folks to configure it in addition to the trust-domain.

Closes #43394

Signed-off-by: stianst [email protected]

@stianst stianst requested a review from a team as a code owner October 14, 2025 05:41
@stianst stianst force-pushed the fix-spiffe-with-iss-claim branch from 1bf858a to d1ff1dc Compare October 14, 2025 05:44
@stianst stianst merged commit 5c5905f into keycloak:main Oct 14, 2025
79 checks passed
stianst added a commit to stianst/keycloak that referenced this pull request Oct 14, 2025
@stianst stianst deleted the fix-spiffe-with-iss-claim branch November 3, 2025 13:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

SPIFFE client authentication does not work when JWT SVID includes iss claim

2 participants