← Back to plugin index

JWT Ticket RSA Signer Settings

Description

Configures RSA based JWT signatures.

This plugin can be used for JWT signature creation. An RSA based signature is created with a private key and must be validated with the corresponding public key.

Type name
JwtTicketRsaSignerSettings
Class
com.airlock.iam.common.application.configuration.jwt.signature.JwtTicketRsaSignerSettings
May be used by
Properties
RSA Signature Algorithm (rsaSignatureAlgorithm)
Description
The algorithm used for signing. Signing requires an RSA private key, which will be obtained from the configured keystore using the configured properties (alias and password).
Attributes
Enum
Optional
Default value
RS512
Keystore Path (keystorePath)
Description
Keystore that holds the private key for JWT token signing.
Attributes
File/Path
Mandatory
Keystore Password (keystorePassword)
Description
Password for the keystore.
Attributes
String
Optional
Sensitive
Private Key Alias (privateKeyAlias)
Description
Alias for the private key contained in the keystore that should be used for signing. This field can be omitted if the keystore only contains one EC private key with the configured password.
Attributes
String
Optional
Private Key Password (privateKeyPassword)
Description
Password for the private key in the keystore.
Attributes
String
Optional
Sensitive
Include KID (includeKid)
Description
If enabled, the KID of the public key used to sign a JWT is added to the JWT header. Consumers of the JWT can use the KID to identify the public key that is verifying the signature.
Attributes
Boolean
Optional
Default value
true
Add x5t#S256 Header Parameter (addX5tS256HeaderParameter)
Description
Indicates whether the x5t#S256 header parameter containing a SHA-256 certificate thumbprint should be added to the JWT header.

The 'Private Key Alias' is used to find the X.509 certificate in the keystore to compute the thumbprint for. I.e., it is assumed that the alias identifies a private key with the corresponding certificate. If no 'Private Key Alias' is configured, the keystore is assumed to contain exactly one certificate.

Attributes
Boolean
Optional
Default value
false
Add x5t Header Parameter (addX5tHeaderParameter)
Description
Indicates whether the x5t header parameter containing a SHA-1 certificate thumbprint should be added to the JWT header.

The 'Private Key Alias' is used to find the X.509 certificate in the keystore to compute the thumbprint for. I.e., it is assumed that the alias identifies a private key with the corresponding certificate. If no 'Private Key Alias' is configured, the keystore is assumed to contain exactly one certificate.

Security warning: SHA-1 fingerprints should no longer be used as SHA-1 is considered broken. We recommend the x5t#S256 thumbprint instead.

Attributes
Boolean
Optional
Default value
false
YAML Template (with default values)

type: JwtTicketRsaSignerSettings
id: JwtTicketRsaSignerSettings-xxxxxx
displayName: 
comment: 
properties:
  addX5tHeaderParameter: false
  addX5tS256HeaderParameter: false
  includeKid: true
  keystorePassword:
  keystorePath:
  privateKeyAlias:
  privateKeyPassword:
  rsaSignatureAlgorithm: RS512