You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
kevinchalet
changed the title
Update the Pro Santé Connect provider to make the ClientCertificate setting required
Update the Pro Santé Connect provider to make the client certificate setting required
Sep 19, 2024
mTLS is now fully supported by the client stack and was successfully tested against Keycloak.
Note: when making the switch, we'll also need to tweak this handler to remove the client_secret_* methods from the supported client authentication methods list if PSC doesn't update their configuration document to reflect this change:
Confirm you've already contributed to this project or that you sponsor it
Describe the solution you'd like
Using mTLS is now mandatory for the sandbox environment and will be required for the production environment in late 2024, as indicated in https://industriels.esante.gouv.fr/produits-et-services/pro-sante-connect/documentation-technique. Since it will stop working with a client certificate after this date, we'll likely want to make it a mandatory setting in OpenIddict.
Additional context
No response
The text was updated successfully, but these errors were encountered: