standards-maintenance
standards-maintenance copied to clipboard
Re-examine how Data Holder Brand JWKS endpoints are to be referenced
Description
There are two areas in the standards where a data holder can describe their JWKS endpoints:
Security Endpoints > JSON Web Key Set End Point - Used to expose public keys to meet OIDC requirements
GetDataHolderBrands > RegisterDataHolderAuth - JWKS endpoint used for authentication by the Data Holder with the Data Recipient. Issue #441 / Register Issue 189 provided clarification on how this endpoint is used,
There is an opportunity to re-evaluate how these fields are being used in production and whether the facilty of two JWKS endpoint configurations adds value or is redundant.