Setting them separately seems more flexible to me. On the other hand, it is
hard for me to imagine a use case where a client would use two different
signature algorithms...
+1 for having two separate options. We can always set them equal in the
Admin Console if we wish.
On Wed, Aug 22, 2018 at 2:12 AM Stian Thorgersen <sthorger(a)redhat.com>
wrote:
Currently, Keycloak always use RS256 both for access tokens and id
tokens.
We're working on introducing support for more algorithms and the ability to
change the default for a realm and also for a client.
Now the question is should have we two options one for access token and
another for ID token. Or just one for both?
_______________________________________________
keycloak-dev mailing list
keycloak-dev(a)lists.jboss.org
https://lists.jboss.org/mailman/listinfo/keycloak-dev