← Back to plugin index

JWT Ticket HMAC Settings

Description

Configures an HMAC for JWTs.

This plugin can be used for JWT signature creation and verification. An HMAC is valid if the same HMAC algorithm and HMAC key are used for creation and validation.

Type name
JwtTicketHmacSettings
Class
com.airlock.iam.common.application.configuration.jwt.signature.JwtTicketHmacSettings
May be used by
Properties
HMAC Algorithm (hmacAlgorithm)
Description
The HMAC algorithm. The configured secret must be long enough for the configured hash function (e.g. >= 512 bits for HS512).
Attributes
Enum
Optional
Default value
HS512
HMAC Key (Base64 Encoded) (hmacKey)
Description

The key for the HMAC function, encoded in base64.
The minimal required length depends on the configured algorithm and must be at least 256 bits. Configuration validation will fail if the secret is too short.

One can, for example, generate a random base64 string with 512 bits (64 bytes) using OpenSSL as follows: openssl rand -base64 64

Attributes
String
Mandatory
Sensitive
YAML Template (with default values)

type: JwtTicketHmacSettings
id: JwtTicketHmacSettings-xxxxxx
displayName: 
comment: 
properties:
  hmacAlgorithm: HS512
  hmacKey: