provide key rollover guidance

Issue #704 resolved
Brian Campbell created an issue

As captured in the 07-Jan-13 call notes http://lists.openid.net/pipermail/openid-specs-ab/Week-of-Mon-20130107/002788.html one of the action items (as I understood it) was for Mr. Bradley to draft some text describing how to accomplish rolling keys given the constructs provided by connect. That was nearly three weeks ago, however, so I'm submitting the ticket on his behalf.

I think https://bitbucket.org/openid/connect/issue/703/key-publication-needs-to-be-reworked needs to be resolved first. Then working though the details of how kid (and maybe x5t) and the x509 and jwk endpoints can be used to rotate keys would be a useful exercise to validate that and might help provide some guidance to implementers and deployers too.

Comments (10)

  1. Log in to comment