Skip to content

OAuth JWT and JWK limits #2722

Aug 17, 2024 · 4 comments · 10 replies
Discussion options

You must be logged in to vote

Old keys should still be advertised in the jwks but no longer used to initiate new sessions. If a key is known to have been compromised, it must be removed from the jwks, effectively preventing it from being used to refresh sessions.

Replies: 4 comments 10 replies

Comment options

You must be logged in to vote
3 replies
@matthieusieben
Comment options

Answer selected by ngerakines
@ngerakines
Comment options

@matthieusieben
Comment options

Comment options

You must be logged in to vote
3 replies
@matthieusieben
Comment options

@ngerakines
Comment options

@matthieusieben
Comment options

Comment options

You must be logged in to vote
4 replies
@ngerakines
Comment options

@ngerakines
Comment options

@matthieusieben
Comment options

@matthieusieben
Comment options

Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants