← Back to plugin index

JWT Ticket Direct AES Encryption Settings

Description

Configures symmetric direct encryption for JWTs.

This plugin can be used for JWT encryption and decryption. To decrypt a JWT the same algorithm and key must be used as for encryption.

Type name
JwtTicketDirectAesEncryptionSettings
Class
com.airlock.iam.common.application.configuration.jwt.encryption.JwtTicketDirectAesEncryptionSettings
May be used by
Properties
Direct Encryption Method (directEncryptionMethod)
Description
The algorithm used for direct encryption. The configured secret must match the length requirements for the configured direct encryption method, see property 'Encryption Key'.
Attributes
Enum
Optional
Default value
A256GCM
Encryption Key (Base64 Encoded) (encryptionKey)
Description

The key for the selected direct encryption method, encoded in base64. The minimal required length depends on the configured encryption method and must be chosen as follows:

  • A128GCM: 128 bits / 16 bytes
  • A192GCM: 192 bits / 24 bytes
  • A256GCM: 256 bits / 32 bytes
  • A128CBC_HS256: 256 bits / 32 bytes
  • A192CBC_HS384: 384 bits / 48 bytes
  • A256CBC_HS512: 512 bits / 64 bytes

One can, for example, generate a random base64 string with 256 bits (32 bytes) using OpenSSL as follows: openssl rand -base64 32

Attributes
String
Mandatory
Sensitive
YAML Template (with default values)

type: JwtTicketDirectAesEncryptionSettings
id: JwtTicketDirectAesEncryptionSettings-xxxxxx
displayName: 
comment: 
properties:
  directEncryptionMethod: A256GCM
  encryptionKey: