JSON Web Key (JWK) Thumbprint was published as RFC 7638.

"JSON Web Key (JWK) Thumbprint," in which Mike Jones and I are credited as co-authors,[RFC 7638] was published.

This standard specifies a method for computing a stable hash value of a JSON Web Key (JWK). Specifically, it describes which fields of the JWK to use in the hash calculation, how to normalize those fields, how to convert the resulting Unicode string into a sequence of bytes, and how to derive a hash value from that sequence. The resulting hash value can be used to identify and select JWKs that hold the key.

James MangerJohn Bradley, and once again performed with great courage. Mike JonesWe would like to express our sincere gratitude to everyone who participated in the security review of this standard.JOSE working group I would also like to thank the Chairs, Area Directors, and everyone at the IETF who has been involved in the development of this standard.

In addition, this JWK Thumbprint is OpenID Connect self-issued ID Token Please note that this is used as the “subject” claim value.

 

[RFC 7638] Jones, M., N. Sakimura:JSON Web Key (JWK) Thumbprint, (2015/9), https://tools.ietf.org/html/rfc7638

 

 

Leave a comment

This site uses Akismet to reduce spam.For details of how to process comment data, please click here.