Package org.keycloak.broker.provider
Class TrustMaterialSdJwtIssuerResolver
java.lang.Object
org.keycloak.broker.provider.TrustMaterialSdJwtIssuerResolver
- All Implemented Interfaces:
TrustedSdJwtIssuerResolver
Bridges a
TrustMaterialIdentityProvider to a TrustedSdJwtIssuerResolver. When the
provider exposes X.509 trust anchors, chain validation is mandated as required by HAIP 6.1.1: the
x5c header of the credential's issuer signed JWT must validate against the anchors and the chain
leaf key verifies the signature, a credential without an x5c header is rejected. Only providers
without X.509 trust anchors fall back to looking up the trusted keys by the issuer key hints
(kid, alg, iss).
TODO: Support looking up the JWKS dynamically from the .well-known/jwt-vc-issuer endpoint of the
issuer in the credential.-
Constructor Summary
ConstructorsConstructorDescriptionTrustMaterialSdJwtIssuerResolver(TrustMaterialIdentityProvider<?> trustMaterial) -
Method Summary
-
Constructor Details
-
TrustMaterialSdJwtIssuerResolver
-
-
Method Details
-
resolve
- Specified by:
resolvein interfaceTrustedSdJwtIssuerResolver- Throws:
VerificationException
-