I'm not sure about the public key hash and the signature hash. Do I really need to compare those two things, or is that not necessary for verifying the JWT?
Okay, I've got this. I need to check that the issuer of the public key is the same as the issuer in the JWT header. That way, I know the public key is from a trusted source.
Hmm, I'm a bit confused. Do I need to check the expiration time of the public key as well as the JWT? I want to make sure the public key is still valid when I'm verifying the signature.
I think I need to check the keyID of the public key and make sure it matches the keyID in the JWT header. That seems like the most straightforward way to ensure I'm using the correct public key.
Jaime
1 month agoFreida
1 month agoKimbery
2 months agoJoanna
2 months agoGlendora
2 months agoGennie
2 months agoHarrison
3 months agoNickolas
3 months agoEmilio
3 months agoXenia
3 months agoErasmo
3 months agoMinna
2 months ago