Skip to content

[S2S] - Ratify Encryption/Client Origin Mechanism #761

Description

@GarethCOliver

This is an issue tracking consensus on the mechanism for encryption in s2s. Current text proposes:

  • Use JWE, mandating HPKE
  • Use JWKs for keys, wrapped to provide attestations (using proofs) and purpose
  • Use nested sign-then-encrypt JWTs for client origin, binding to jwk thumbprint

Still TODO: if we have any mandated supported curves and how to do post-quantum.

Metadata

Metadata

Assignees

No one assigned

    Type

    No fields configured for Task.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions