← Back to plugin index

RSA Sign Ticket Encoder

Description
Encodes the ticket with an RSA Signature without encryption.

The ticket value syntax is as follows:
{name=[value{,value}];} where the names, values and rolenames are UTF-8 encoded.

Example:
medusaID=1234;uname=smith;roles=customer,employee;name1=value1;name2=value2;

The ticket string (as above) is interpreted as byte array (ASCII encoding) from here on. The expiry date is appended to the ticket string: The milliseconds since midnight 01.01.1970 appended as 64 bit signed integer (MSB first).

An RSA signature is calculated over the result from above and preprended to the result from above.

Use openssl to produce the key files like this:
openssl genrsa -out signkey.pem 4096
openssl pkcs8 -topk8 -nocrypt -in signkey.pem -outform der -out signkey.pkcs8
openssl rsa -in signkey.pem -pubout -outform der -out verifykey.x509
Type name
RSASignTicketEncoder
Class
com.airlock.iam.core.misc.util.ticket.codec.sign.RSASignTicketEncoder
May be used by
Properties
Signing Key File (signingKeyFile)
Description
The Filename of the PKCS#8 encoded RSA private key for signing.
Attributes
File/Path
Mandatory
Compress (compress)
Description
Tells if the value should be GZIP compressed before base64 encoding.
Attributes
Boolean
Optional
Default value
false
YAML Template (with default values)

type: RSASignTicketEncoder
id: RSASignTicketEncoder-xxxxxx
displayName: 
comment: 
properties:
  compress: false
  signingKeyFile: