OIDC: document ECDSA signing method support

Chris Lu
2026-01-29 19:24:42 -08:00
parent b21387cdcd
commit 58235bfdb1
2 changed files with 3 additions and 1 deletions
+2
@@ -24,6 +24,7 @@ SeaweedFS uses Go's standard library cryptographic packages (`crypto/*`) for all
| S3 Signature V4 | HMAC-SHA256 | AWS-compatible request signing |
| S3 Signature V2 | HMAC-SHA1 | Legacy AWS signature support |
| JWT Tokens | HMAC-SHA256 | For volume server and filer access control |
| OIDC Tokens | RSA, ECDSA | For OIDC identity provider integration |
| SSE-C Key Validation | MD5 | For key integrity verification (AWS S3 compatible) |
### Transport Encryption (In Transit)
@@ -45,6 +46,7 @@ All cryptographic algorithms used by SeaweedFS are **FIPS-approved**:
| SSE-C Encryption | AES-256-CTR | ✅ Approved |
| S3 Signatures | HMAC-SHA256 | ✅ Approved |
| Hashing | SHA-256 | ✅ Approved |
| OIDC Validation | RSA, ECDSA | ✅ Approved |
| Transport | TLS 1.2/1.3 | ✅ Approved |
| Legacy S3 Signatures | HMAC-SHA1 | ⚠️ Approved (use V4 preferred) |
| SSE-C Key Validation | MD5 | ⚠️ Used for AWS S3 compatibility only |
+1 -1
@@ -10,7 +10,7 @@
This guide shows how to integrate OpenID Connect (OIDC) identity providers with SeaweedFS S3 Gateway using the advanced IAM and STS configuration. It supports:
- Direct OIDC authentication to S3 with Bearer tokens
- Direct OIDC authentication to S3 with Bearer tokens (RSA and ECDSA)
- OIDC to STS role assumption using trust policies and role mapping
## Supported Identity Providers