← Back to plugin index

JWT Ticket EC Verifier Settings

Description

Configures the EC based JWT signature verifier.

This plugin can be used for JWT signature verification. An EC based signature is created with a private key and must be validated with the corresponding public key.

Type name
JwtTicketEcVerifierSettings
Class
com.airlock.iam.common.application.configuration.jwt.signature.JwtTicketEcVerifierSettings
May be used by
Properties
EC Signature Algorithm (ecSignatureAlgorithm)
Description
The algorithm used for signature verifying. Signature verification requires an EC certificate (public key), which will be obtained from the configured keystore using the configured alias.

According to the selected algorithm, the private key must be derived from a specific curve:
  • ES512: NIST Curve P521
  • ES384: NIST Curve P384
  • ES256: NIST Curve P256
Attributes
Enum
Optional
Default value
ES512
Keystore Path (keystorePath)
Description
Keystore that holds the certificate containing the public key for JWT signature verification. Alternatively, it can be a file containing a PEM encoded public key.
Attributes
File/Path
Mandatory
Keystore Password (keystorePassword)
Description
Password for the keystore.
Attributes
String
Optional
Sensitive
X.509 Certificate Alias (x509CertificateAlias)
Description
Alias for the X.509 certificate contained in the keystore that should be used for signature verification. This field can be omitted if the keystore only contains one X.509 certificate with a public key.
Attributes
String
Optional
YAML Template (with default values)

type: JwtTicketEcVerifierSettings
id: JwtTicketEcVerifierSettings-xxxxxx
displayName: 
comment: 
properties:
  ecSignatureAlgorithm: ES512
  keystorePassword:
  keystorePath:
  x509CertificateAlias: