Skip to content

Reload the key set for tokens signed with an unknown key - #79

Open
robertlemke wants to merge 1 commit into
mainfrom
task/refetch-jwks-for-unknown-key
Open

robertlemke wants to merge 1 commit into
mainfrom
task/refetch-jwks-for-unknown-key

Conversation

@robertlemke

Copy link
Copy Markdown
Member

Tokens signed with a key which the identity provider published after the key set was cached are now accepted. If a token names a key identifier ("kid") which the cached JSON Web Key Set doesn't contain, the provider loads the key set again and verifies the signature with it. This also covers identity tokens received by a refresh, which after a rotation are often the first ones signed with the new key.

The key set is reloaded at most once per minute, even if the request fails, so that tokens with made-up key identifiers can't flood the identity provider with requests. Tokens without a key identifier don't trigger a reload.

Resolves #71

The authentication provider now loads the JSON Web Key Set of the
identity provider again if a token names a key identifier which the
cached key set doesn't contain. This also applies to identity tokens
received by a refresh. The key set is reloaded at most once per minute,
even if the request fails.

Previously, the key set was only retrieved when the cache was empty.
Identity providers like Microsoft Entra ID rotate their signing keys.
Tokens signed with a new key were rejected until the cache entry
expired or somebody flushed the cache, and logins failed in the
meantime.

The minimum interval keeps tokens with made-up key identifiers from
flooding the identity provider with requests. Tokens without a key
identifier don't trigger a reload, because a failed signature can't
tell a rotated key from a forged token in that case.

Resolves: #71
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Feature Request: Auto renew identity provider key for signing

1 participant