← Back to plugin index

OIDC Private Key JWT Client Authentication

Description
Allows clients that have previously registered a public key on the authorization server to sign a JWT using the corresponding private key in order to authenticate with the authorization server.

The JWT is formatted according to the private_key_jwt client authentication as specified by the OpenID Connect Core Specification.

Type name
OpenIDConnectPrivateKeyJwtClientAuthentication
Class
com.airlock.iam.oauth2.application.configuration.signature.OpenIDConnectPrivateKeyJwtClientAuthenticationConfig
May be used by
License-Tags
OAuthClient
Properties
Custom Audience (customAudience)
Description
Custom value used as audience claim (aud) of the JWT. According to the OpenID Connect Core Specification, the audience SHOULD be the URL of the authorization server's token endpoint. If not configured, the authorization server's token endpoint URL is used as "aud" claim.
Attributes
String
Optional
Example
https://airlock.com/auth/rest/oauth2/authorization-servers/as/token
Example
https://accounts.google.com/o/oauth2/token
Example
https://login.live.com/oauth20_token.srf
JWT Validity [s] (validityDuration)
Description
The duration (in seconds) for which the generated JWT will be accepted by the authorization server. Will be used for calculating the exp of the JWT.
Attributes
Integer
Optional
Default value
60
Valid Not Before Skew (validNotBeforeSkew)
Description
This claim identifies the time before which the JWT must not be accepted for processing. To determine the nbf claim value in the JWT, the number of seconds configured in this property are subtracted from the JWT issue time. The motivation to set a time in the past is to avoid clock synchronization problems with the authorization server.
Attributes
Integer
Optional
Default value
5
Include KID (includeKid)
Description

If enabled the KID of the public key used to sign a JWT is added to the JWT header. Consumers of the JWT can use the KID to identify the public key that is verifying the signature.

The KID is ignored by some servers but is usually necessary when the client has multiple keys (or wants to rotate them) or when the authorization server needs to look up the corresponding public key on the client's JWKS endpoint.

This property's testlet displays the KID that is included in the JWT header if the property is enabled.

Attributes
Boolean
Optional
Default value
true
Algorithm (algorithm)
Description
Private key based signature algorithm to use.
Attributes
Enum
Optional
Default value
RS256
Keystore File (keystoreFile)
Description
Keystore file name containing the certificate and key used to sign the JWT.
Attributes
File/Path
Mandatory
Keystore Password (keystorePassword)
Description
The password used to open the keystore.
Attributes
String
Optional
Sensitive
Signing Key Alias (signingKeyAlias)
Description
The alias of the key used to sign the JWT. This field can be omitted if the keystore only contains one private key entry.
Attributes
String
Optional
Example
alias
Signing Key Password (signingKeyPassword)
Description
The password used to retrieve the key from the keystore. This password can be the same as the keystore password.
Attributes
String
Mandatory
Sensitive
YAML Template (with default values)

type: OpenIDConnectPrivateKeyJwtClientAuthentication
id: OpenIDConnectPrivateKeyJwtClientAuthentication-xxxxxx
displayName: 
comment: 
properties:
  algorithm: RS256
  customAudience:
  includeKid: true
  keystoreFile:
  keystorePassword:
  signingKeyAlias:
  signingKeyPassword:
  validNotBeforeSkew: 5
  validityDuration: 60