Dear Partners,
We would like to inform you that the Corppass enhancement to disallow HTTPS redirects on clients' configured JSON Web Key Set (JWKS) URLs has now been successfully deployed to the Production environment.
As previously communicated, this change means that Corppass will only accept direct responses from the configured JWKS endpoint during key retrieval. Any configured JWKS URL that returns an HTTPS redirect will no longer be accepted.
If you have already reviewed your JWKS URL configuration and confirmed that it directly serves the JWKS document, no further action is required.
If your JWKS URL still relies on HTTPS redirects, please update your configuration immediately. Failure to do so may result in authentication failures for your OIDC client(s).
If you experience any issues following this deployment or require assistance, please contact us here.
Thank you for your cooperation and continued support.
Best regards,
Corppass Team
Comments
0 comments
Please sign in to leave a comment.