Class AuthorizationServerKeys

java.lang.Object
com.codename1.backend.security.oauth2.server.authorization.AuthorizationServerKeys

public final class AuthorizationServerKeys extends Object

The keys an authorization server signs with.

cn1.security.authorizationserver.jwk.keys=/etc/acme/signing-2026.pem,/etc/acme/signing-2025.pem

Each is a PEM file holding an RSA or a P-256 private key. The first signs every new token; all of them are published at the JWK Set endpoint, so that a token signed by the key that was first until yesterday still verifies. To rotate, put the new key first and keep the old one in the list for as long as its tokens live.

A key can be made with

openssl genpkey -algorithm RSA -pkeyopt rsa_keygen_bits:2048 -out signing.pem

On a development profile with no key set, a key is made when the server starts and a warning says so: every restart then invalidates every token. Anywhere else a missing key stops the server from starting.

An application that issues tokens of its own -- a long-lived token for a build agent -- declares the keys and an encoder as beans, and the authorization server uses the same ones:

@Bean
JwkSource signingKeys(Config config) throws IOException {
    return AuthorizationServerKeys.load(config);
}

@Bean
JwtEncoder jwtEncoder(JwkSource keys) {
    return new DefaultJwtEncoder(keys);
}
  • Field Details

  • Method Details

    • load

      public static JwkSource load(Config config) throws IOException

      The keys the configuration names, the signing one first.

      • IllegalStateException: when none is set outside a development profile, or one of them is not a key this server signs with
      Throws:
      IOException
    • of

      public static JwkSource of(List<Jwk> keys)
      A source of exactly these keys, the signing one first.
    • usable

      public static Jwk usable(Jwk key, String where)

      key marked as a signing key under the algorithm its kind signs with.

      • IllegalStateException: when it is neither RSA nor P-256
    • algorithm

      public static String algorithm(Jwk key)
      RS256 for an RSA key, ES256 for a P-256 one, null for any other.