Builds the x5c or x5u header members for one signature by the ambient realm's key named by kid.
x5c
x5u
kid
The policy is jose_certificate_header.js's; this finds the key and its public half without touching a private key.
jose_certificate_header.js
a row of jose_certificate_header.js's use cases
the JWS algorithm
the signing key's kid
the header members to merge; {} for HMAC, a key this realm does not hold, or a use case that gets nothing
{}
Builds the
x5corx5uheader members for one signature by the ambient realm's key named bykid.The policy is
jose_certificate_header.js's; this finds the key and its public half without touching a private key.