wycheproof-jwk-ambiguous
JWK: Ambiguous
Marks test vectors with behavior that is not well defined by the RFCs. Best practice is to reject such cases.
REJECT
Your service should reject this one.
Stated as the outcome to assert against, so a suite compares with this rather than hardcoding a result and getting it backwards.
Marks test vectors with behavior that is not well defined by the RFCs. Best practice is to reject such cases. Demonstrated by 2 test vectors in Project Wycheproof.
Provenance
- Kind
- hardeningDefensible practice with no normative source. Judge it for yourself.
- Source
- wycheproof
- Clause
- RFC 7517
- CVE
- none
- Weakness
- none
Test keys only. Nothing here is a statement about any particular service: the expected outcome above is what an application ought to do, not evidence that yours does.