secp256k1 key still present in did.json after FIPS retirement notice – is this expected?

Dennis Gärtig 20 Zuverlässigkeitspunkte
2026-06-11T12:18:06.4+00:00

We received the Microsoft retirement notification stating that non-FIPS signing keys (secp256k1 / P-256K) will no longer be supported starting July 1, 2026.

We checked our setup and confirmed we are using Quick Setup – our DID starts with did:web:verifiedid.entra.microsoft.com. According to the documentation, Quick Setup tenants should already be FIPS compliant using P-256 keys.

However, when we retrieved our did.json document, we found 15 keys with crv: P-256 (all named ...managedsigp256) but also one key with crv: secp256k1:

{
"id": "#...serviceManagedSign",
"type": "EcdsaSecp256k1VerificationKey2019",
"publicKeyJwk": {
  "crv": "secp256k1"
}
}

This secp256k1 key is also listed in the assertionMethod array.

We do not have a custom Azure Key Vault configured – the signing keys are Microsoft-managed.

Our questions:

  1. Is it expected for a Quick Setup tenant to still have a secp256k1 key in the DID document?
  2. Is this key still used for active signing of new credentials, or only kept for validating previously issued credentials?
  3. Do we need to take any action before July 1, 2026, or are we already compliant?

Thank you.

Azure Key Vault
Azure Key Vault

Ein Azure-Dienst, der zum Verwalten und Schützen von Kryptografieschlüsseln und anderen Geheimnissen verwendet wird, die von Cloud-Apps und -Diensten verwendet werden


Antwort, die vom Frageautor angenommen wurde
Sridevi Machavarapu 33,820 Zuverlässigkeitspunkte Externe Microsoft-Mitarbeiter Moderator
2026-06-11T12:42:46.23+00:00

Hello Dennis Gärtig,

Yes, what you’re seeing can happen, and it doesn’t mean you’re non‑compliant.

For Quick Setup (your DID starts with did:web:verifiedid.entra.microsoft.com), Microsoft already uses P‑256 keys for signing, so you’re covered from a FIPS standpoint.

The important detail is how DID documents are handled. When keys change or are rotated, the generated did.json can include both the new P‑256 key and the older secp256k1 key at the same time. So, seeing a secp256k1 entry doesn’t necessarily mean it’s still being used for issuing new credentials.

In practice, this usually means:

  • New credentials are signed with the P‑256 key
  • The older secp256k1 key is still published so previously issued credentials can be validated

You don’t need to take any action. The upgrade guidance only applies to tenants using Advanced Setup with P‑256K keys. Quick Setup authorities are already managed and compliant, and Microsoft handles the key lifecycle.

Reference:

War diese Antwort hilfreich?

Eine Person fand diese Antwort hilfreich.

0 zusätzliche Antworten

Sortieren nach: Am hilfreichsten

Ihre Antwort

Antworten können von Fragestellenden als „Angenommen“ und von Moderierenden als „Empfohlen“ gekennzeichnet werden, wodurch Benutzende wissen, dass diese Antwort das Problem des Fragestellenden gelöst hat.