Class TrustMaterialSdJwtIssuerResolver

java.lang.Object
org.keycloak.broker.provider.TrustMaterialSdJwtIssuerResolver
All Implemented Interfaces:
TrustedSdJwtIssuerResolver

public class TrustMaterialSdJwtIssuerResolver extends Object implements TrustedSdJwtIssuerResolver
Bridges a TrustMaterialIdentityProvider to a TrustedSdJwtIssuerResolver. When the provider exposes X.509 trust anchors, chain validation is mandated as required by HAIP 6.1.1: the x5c header of the credential's issuer signed JWT must validate against the anchors and the chain leaf key verifies the signature, a credential without an x5c header is rejected. Only providers without X.509 trust anchors fall back to looking up the trusted keys by the issuer key hints (kid, alg, iss). TODO: Support looking up the JWKS dynamically from the .well-known/jwt-vc-issuer endpoint of the issuer in the credential.