Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Workload identity URI in other fields #28

Open
jsalowey opened this issue Jun 29, 2024 · 3 comments
Open

Workload identity URI in other fields #28

jsalowey opened this issue Jun 29, 2024 · 3 comments

Comments

@jsalowey
Copy link
Collaborator

The WIT URI appears in the subject of a cert and token, but shouild it also be used for the issuer of the token and the CA subject name of a certificate.

@yaronf
Copy link
Collaborator

yaronf commented Jun 30, 2024

Also potentially aud.

@bc-pi
Copy link
Collaborator

bc-pi commented Jun 30, 2024

The WIT URI appears in the [...]

I am admittedly confused by what a "WIT URI" might be.

@PieterKas
Copy link

Commenting as an identity enthusiast as opposed to chair:

I like the idea of using the same identifier format for all entities, but I do wonder if that is necessary. For a Bring Your own PKI scenario it may not be possible to change the issuer identifier for the CA, and the aud laim may correspond to the aud claim in the access token instead of some other workload identity (not sure those are constrained to aud).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants