Skip to content

Size of generated client key #19

@chulkilee

Description

@chulkilee

private_key = JOSE.JWK.generate_key({:rsa, 1024, 65_537})

It uses 1024-bit key, which may not be suitable for alg (e.g. RS256 in the client creation doc.).

Is Boruta.Oauth.Client's id_token_signature_alg for id_token_signed_response_alg in the spec? The spec says its default should be RS256 (if omitted) but Boruta uses RS512 for new client. It's not "against" spec but I'm wondering why it choose RS512.

We may introduce an option for the default key size of generated key pairs.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions