Version Affected: All
Overview
This article explains how to change the signing certificate algorithm for a SecureAuth CloudEntity Workspace's OAuth tokens, choosing between RSA and Elliptic Curve Digital Signature Algorithm (ECDSA).
Change the Signing Certificate Algorithm
- Sign in to CloudEntity and, in the correct Workspace, go to OAuth > Tokens > Signing and Encryption.
- Scroll down to Signing key rotation settings.
- Under Manual key rotation, select Rotate key.
This action cannot be undone. Once you confirm the rotation, the current signing key is replaced by the next key in queue, and a new key with the algorithm you select becomes the next key in queue. Any Service Provider still using the previous signing key's public key will need to be updated.
- In the Rotate Signing Keys dialog, under Select the token signing algorithm type, choose RSA or ECDSA for the new key.
- Select Rotate keys to confirm.
The key that was previously Next key in queue becomes the Current key in use, and the newly created key, with the algorithm you selected, becomes the new Next key in queue.
For more information, see CloudEntity's Signing Keys Management documentation.
Special Considerations
Rotating a signing key cannot be undone. Confirm that every Service Provider using the current signing key's public key is ready to pick up the new key before you rotate, since tokens signed with a revoked key will no longer validate.
SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.
Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.
Comments
Please sign in to leave a comment.