Allow JWKS refresh to invalidate keys even on failure

XMLWordPrintableJSON

    • Type: Task
    • Resolution: Fixed
    • Priority: Major - P3
    • 7.0.0-rc0
    • Affects Version/s: None
    • Component/s: None
    • None
    • Server Security
    • Fully Compatible
    • Security 2023-02-20, Security 2023-03-06
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      If forced JWKS refresh fails, any cached JWKSes are left active in memory. This preserves availability. However, administrators perform JWKS refresh to recover from IdP private key compromise. It can be important for compromised key material to be distrusted, even if we are unable to obtain fresh, valid, material.

      We should introduce a mechanism which lets us flush JWKS even on re-acquisition failure.

            Assignee:
            Adrian Gonzalez Montemayor
            Reporter:
            Spencer Jackson
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Created:
              Updated:
              Resolved: