Interface TrustMaterialIdentityProvider<C extends IdentityProviderModel>

All Superinterfaces:
IdentityProvider<C>, Provider
All Known Implementing Classes:
DefaultTrustIdentityProvider, GitLabIdentityProvider, GoogleIdentityProvider, KeycloakOIDCIdentityProvider, LinkedInOIDCIdentityProvider, OID4VPIdentityProvider, OIDCIdentityProvider

public interface TrustMaterialIdentityProvider<C extends IdentityProviderModel> extends IdentityProvider<C>
Identity providers that expose reusable trust material for flows such as client attestation or OID4VCI key attestation.
  • Method Details

    • resolveKeys

      Stream<JWK> resolveKeys(TrustMaterialRequest request)
    • resolveX509Trust

      default Stream<X509TrustMaterial> resolveX509Trust(TrustMaterialRequest request)
      Resolves X.509 trust anchors and policy. Providers that only expose JWKs do not need to implement this method.
    • validateX509Chain

      default JWK validateX509Chain(TrustMaterialRequest request, List<String> x5c, String algorithm) throws VerificationException
      Validates the x5c certificate chain of a presented artifact against this provider's X.509 trust material and returns the chain leaf key. Exposing X.509 trust anchors mandates chain validation: a missing or unverifiable chain fails.
      Returns:
      the leaf key of the validated chain, or null when this provider exposes no X.509 trust material
      Throws:
      VerificationException
    • validateX509Chain

      static JWK validateX509Chain(List<X509TrustMaterial> trustMaterials, List<String> x5c, String algorithm) throws VerificationException
      Validates the x5c certificate chain against the given trust materials and returns the chain leaf key. The materials are tried in order and the first successful validation wins.
      Returns:
      the leaf key of the validated chain, or null if no trust material was given
      Throws:
      VerificationException