← Back to plugin index

JWT Ticket EC Signer Settings

Description

Configures EC based JWT signatures.

This plugin can be used for JWT signature creation. An EC based signature is created with a private key and must be validated with the corresponding public key.

Type name
JwtTicketEcSignerSettings
Class
com.airlock.iam.common.application.configuration.jwt.signature.JwtTicketEcSignerSettings
May be used by
Properties
EC Signature Algorithm (ecSignatureAlgorithm)
Description
The algorithm used for signing. Signing requires an EC private key, which will be obtained from the configured keystore using the configured properties (alias and password).

According to the selected algorithm, the private key must be derived from a specific curve:
  • ES512: NIST Curve P521
  • ES384: NIST Curve P384
  • ES256: NIST Curve P256
Attributes
Enum
Optional
Default value
ES512
Keystore Path (keystorePath)
Description
Keystore that holds the private key for JWT token signing.
Attributes
File/Path
Mandatory
Keystore Password (keystorePassword)
Description
Password for the keystore.
Attributes
String
Optional
Sensitive
Private Key Alias (privateKeyAlias)
Description
Alias for the private key contained in the keystore that should be used for signing. This field can be omitted if the keystore only contains one EC private key with the configured password.
Attributes
String
Optional
Private Key Password (privateKeyPassword)
Description
Password for the private key in the keystore.
Attributes
String
Optional
Sensitive
Include KID (includeKid)
Description
If enabled, the KID of the public key used to sign a JWT is added to the JWT header. Consumers of the JWT can use the KID to identify the public key that is verifying the signature.
Attributes
Boolean
Optional
Default value
true
Add x5t#S256 Header Parameter (addX5tS256HeaderParameter)
Description
Indicates whether the x5t#S256 header parameter containing a SHA-256 certificate thumbprint should be added to the JWT header.

The 'Private Key Alias' is used to find the X.509 certificate in the keystore to compute the thumbprint for. I.e., it is assumed that the alias identifies a private key with the corresponding certificate. If no 'Private Key Alias' is configured, the keystore is assumed to contain exactly one certificate.

Attributes
Boolean
Optional
Default value
false
Add x5t Header Parameter (addX5tHeaderParameter)
Description
Indicates whether the x5t header parameter containing a SHA-1 certificate thumbprint should be added to the JWT header.

The 'Private Key Alias' is used to find the X.509 certificate in the keystore to compute the thumbprint for. I.e., it is assumed that the alias identifies a private key with the corresponding certificate. If no 'Private Key Alias' is configured, the keystore is assumed to contain exactly one certificate.

Security warning: SHA-1 fingerprints should no longer be used as SHA-1 is considered broken. We recommend the x5t#S256 thumbprint instead.

Attributes
Boolean
Optional
Default value
false
YAML Template (with default values)

type: JwtTicketEcSignerSettings
id: JwtTicketEcSignerSettings-xxxxxx
displayName: 
comment: 
properties:
  addX5tHeaderParameter: false
  addX5tS256HeaderParameter: false
  ecSignatureAlgorithm: ES512
  includeKid: true
  keystorePassword:
  keystorePath:
  privateKeyAlias:
  privateKeyPassword: