Ein Azure-Dienst, der zum Verwalten und Schützen von Kryptografieschlüsseln und anderen Geheimnissen verwendet wird, die von Cloud-Apps und -Diensten verwendet werden
Hello Dennis Gärtig,
Yes, what you’re seeing can happen, and it doesn’t mean you’re non‑compliant.
For Quick Setup (your DID starts with did:web:verifiedid.entra.microsoft.com), Microsoft already uses P‑256 keys for signing, so you’re covered from a FIPS standpoint.
The important detail is how DID documents are handled. When keys change or are rotated, the generated did.json can include both the new P‑256 key and the older secp256k1 key at the same time. So, seeing a secp256k1 entry doesn’t necessarily mean it’s still being used for issuing new credentials.
In practice, this usually means:
- New credentials are signed with the P‑256 key
- The older secp256k1 key is still published so previously issued credentials can be validated
You don’t need to take any action. The upgrade guidance only applies to tenants using Advanced Setup with P‑256K keys. Quick Setup authorities are already managed and compliant, and Microsoft handles the key lifecycle.
Reference: