← Back to plugin index

JWE Password Decryption

Description

Decryption service accepting encrypted passwords in JWE format (as specified in https://tools.ietf.org/html/rfc7516).

The encryption information contained in the step responses (additional data "e2eEncryptionInformation") consists of a type (always "type"="JWE"), a nonce (element "nonce") and the public key of the configured key pair in JWK format (element "publicKey").

The password sent by the client for verification must be encrypted in JWE format and include the nonce in the header. The JWE payload must include the password as a JSON string. The location of the password in the payload JSON structure can be configured. By default the JWE payload is expected to be in the following format:

{
    "header": {
        "nonce":"si04fHDORRELOO0T4nJad8mz9DgPPE9GhArD2reQ2Dk=",
        "alg":"RSA-OAEP-256",
        "enc":"A128GCM"
     },
    "password":"userPasswordInPlaintext"
}

For decryption, the private key of the configured "Key Pair" is used.

Type name
JwePasswordDecryption
Class
com.airlock.iam.common.application.configuration.e2ee.JwePasswordDecryptionConfig
May be used by
License-Tags
EndToEndPasswordEncryption
Properties
Password Json Path (passwordJsonPath)
Description
The path which points to the password contained in the payload of the JWE in JSON Pointer format as specified in https://tools.ietf.org/html/rfc6901 The referenced plaintext password must be a JSON string.

If for example the payload of the JWE looks as follows:

{
  "user": {
    "id": "8331-1212-1233",
    "password": "userPasswordInPlaintext"
    }
}
Then the following JSON Pointer should be configured in order to use "userPasswordInPlaintext" for the password check: /user/password
Attributes
String
Optional
Default value
/password
Example
/password
Example
/user/passwords/0
Key Pair (keyPair)
Description
The configuration of the public/private keypair used for encrypting/decrypting the passwords. The public key information, needed for encrypting the JWE, will be returned by the flow step.
Attributes
Plugin-Link
Mandatory
Assignable plugins
YAML Template (with default values)

type: JwePasswordDecryption
id: JwePasswordDecryption-xxxxxx
displayName: 
comment: 
properties:
  keyPair:
  passwordJsonPath: /password