Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update JWS documentation to reflect mandatory use of certificates for embedding JWS public keys #110

Open
bushjames opened this issue May 8, 2024 · 4 comments
Assignees

Comments

@bushjames
Copy link

bushjames commented May 8, 2024

Current documentation here: https://docs.mojaloop.io/api/fspiop/pki-best-practices.html#json-web-signature says that certificates should be used for handling JWS public keys. At the DA meeting on 2024-05-08 it was agreed by those present to update this wording thus:

  1. change the word should to must
  2. add some explanation of the rationale behind this requirement.
@bushjames
Copy link
Author

@elnyry-sam-k to raise this with CCB and report back to DA at next available opportunity.

@bushjames
Copy link
Author

CCB have agreed, FSPIOP SIG will be approached next.

@henrka
Copy link

henrka commented Sep 12, 2024

FSPIOP SIG is OK with the suggestion above.

henrka added a commit to mojaloop/mojaloop-specification that referenced this issue Sep 19, 2024
Change as per suggestion in mojaloop/design-authority-project#110.
Bumped version of PKI Best Practices to 1.0.1. Not considered a breaking change in any way as it is a best practices document and the use of certificates is industry standard.
@bushjames
Copy link
Author

Update expected in v2.0 of docs site; coming soon.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants