JWT Ticket EC Signer Settings
Configures EC based JWT signatures.
This plugin can be used for JWT signature creation. An EC based signature is created with a private key and must be validated with the corresponding public key.
ecSignatureAlgorithm) According to the selected algorithm, the private key must be derived from a specific curve:
- ES512: NIST Curve P521
- ES384: NIST Curve P384
- ES256: NIST Curve P256
keystorePath) keystorePassword) privateKeyAlias) privateKeyPassword) includeKid) addX5tS256HeaderParameter) The 'Private Key Alias' is used to find the X.509 certificate in the keystore to compute the thumbprint for. I.e., it is assumed that the alias identifies a private key with the corresponding certificate. If no 'Private Key Alias' is configured, the keystore is assumed to contain exactly one certificate.
addX5tHeaderParameter) The 'Private Key Alias' is used to find the X.509 certificate in the keystore to compute the thumbprint for. I.e., it is assumed that the alias identifies a private key with the corresponding certificate. If no 'Private Key Alias' is configured, the keystore is assumed to contain exactly one certificate.
Security warning: SHA-1 fingerprints should no longer be used as SHA-1 is considered broken. We recommend the x5t#S256 thumbprint instead.
type: JwtTicketEcSignerSettings
id: JwtTicketEcSignerSettings-xxxxxx
displayName:
comment:
properties:
addX5tHeaderParameter: false
addX5tS256HeaderParameter: false
ecSignatureAlgorithm: ES512
includeKid: true
keystorePassword:
keystorePath:
privateKeyAlias:
privateKeyPassword: