You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
It seems to me that confirming the chain of trust from an installed root CA to the specified issuer merely ensures that the server is who it says it is, it doesn't mean that you should trust that server as an issuer of JWT for this system?
The text was updated successfully, but these errors were encountered:
I've seen guidance that the
iss
claim should not be blindly followed but should be subject to an allow list... e.g. see https://curity.io/resources/learn/jwt-best-practices/#5-always-check-the-issuer.It seems to me that confirming the chain of trust from an installed root CA to the specified issuer merely ensures that the server is who it says it is, it doesn't mean that you should trust that server as an issuer of JWT for this system?
The text was updated successfully, but these errors were encountered: