I found solution. I used parameter jwks_ca_pem=@<path_to_pem>
It is documented under below link but it wasn’t that obvious when I checked this document first time.
JWT/OIDC - Auth Methods - HTTP API | Vault | HashiCorp Developer
2 Likes