JWE Password Decryption
Decryption service accepting encrypted passwords in JWE format (as specified in https://tools.ietf.org/html/rfc7516).
The encryption information contained in the step responses (additional data "e2eEncryptionInformation") consists of a type (always "type"="JWE"), a nonce (element "nonce") and the public key of the configured key pair in JWK format (element "publicKey").
The password sent by the client for verification must be encrypted in JWE format and include the nonce in the header. The JWE payload must include the password as a JSON string. The location of the password in the payload JSON structure can be configured. By default the JWE payload is expected to be in the following format:
{
"header": {
"nonce":"si04fHDORRELOO0T4nJad8mz9DgPPE9GhArD2reQ2Dk=",
"alg":"RSA-OAEP-256",
"enc":"A128GCM"
},
"password":"userPasswordInPlaintext"
}For decryption, the private key of the configured "Key Pair" is used.
passwordJsonPath) If for example the payload of the JWE looks as follows:
{
"user": {
"id": "8331-1212-1233",
"password": "userPasswordInPlaintext"
}
}
Then the following JSON Pointer should be configured in order to use "userPasswordInPlaintext" for the password check: /user/password keyPair)
type: JwePasswordDecryption
id: JwePasswordDecryption-xxxxxx
displayName:
comment:
properties:
keyPair:
passwordJsonPath: /password