[TIP] Apache module to authenticate a NativeSPApacheConfig to the backend app and sign attributes

Peter Schober peter.schober at univie.ac.at
Fri May 4 05:22:57 EDT 2018


* Tom Noonan <tom at joinroot.com> [2018-05-03 18:22]:
> - mod_proxy_jwt_auth will add Shibboleth environment variables to
> the token and sign them.  When signature verification is on then the
> backend server can be confident the header variables are not
> spoofed.

So no confidentiality (encryption)?
How about key rollover for the signing key, with potentially dozens
(or more) of JWT "clients"?
-peter


More information about the users mailing list