Uses of Package
org.keycloak.broker.spiffe
Packages that use org.keycloak.broker.spiffe
-
Classes in org.keycloak.broker.spiffe used by org.keycloak.broker.spiffeClassDescriptionImplementation for https://datatracker.ietf.org/doc/draft-schwenkschuster-oauth-spiffe-client-auth/ Main differences for SPIFFE JWT SVIDs and regular client assertions:
jwt-spiffeclient assertion typeissclaim is optional, uses SPIFFE IDs, which includes trust domain insteadjticlaim is optional, and SPIFFE vendors re-use/cache tokenssubis a SPIFFE ID with the syntaxspiffe://trust-domain/workload-identityKeys are fetched from a SPIFFE bundle endpoint, where the JWKS has additional SPIFFE specific fields (spiffe_sequenceandspiffe_refresh_hint, the JWK does not set thealg>