Class AuthorizationServerKeys
The keys an authorization server signs with.
cn1.security.authorizationserver.jwk.keys=/etc/acme/signing-2026.pem,/etc/acme/signing-2025.pem
Each is a PEM file holding an RSA or a P-256 private key. The first signs every new token; all of them are published at the JWK Set endpoint, so that a token signed by the key that was first until yesterday still verifies. To rotate, put the new key first and keep the old one in the list for as long as its tokens live.
A key can be made with
openssl genpkey -algorithm RSA -pkeyopt rsa_keygen_bits:2048 -out signing.pem
On a development profile with no key set, a key is made when the server starts and a warning says so: every restart then invalidates every token. Anywhere else a missing key stops the server from starting.
An application that issues tokens of its own -- a long-lived token for a build agent -- declares the keys and an encoder as beans, and the authorization server uses the same ones:
@Bean
JwkSource signingKeys(Config config) throws IOException {
return AuthorizationServerKeys.load(config);
}
@Bean
JwtEncoder jwtEncoder(JwkSource keys) {
return new DefaultJwtEncoder(keys);
}
-
Field Summary
Fields -
Method Summary
Modifier and TypeMethodDescriptionstatic StringRS256for an RSA key,ES256for a P-256 one, null for any other.static JwkSourceThe keys the configuration names, the signing one first.static JwkSourceA source of exactly these keys, the signing one first.static Jwkkeymarked as a signing key under the algorithm its kind signs with.
-
Field Details
-
KEYS
The setting that lists the key files, separated by commas.- See Also:
-
-
Method Details
-
load
The keys the configuration names, the signing one first.
IllegalStateException: when none is set outside a development profile, or one of them is not a key this server signs with
- Throws:
IOException
-
of
-
usable
-
algorithm
-