How To: Change the CloudEntity Signing Certificate Algorithm

Follow
    Applies to:
  • CloudEntity
Deployment model:
  • Cloud
  • Version Affected: All

     

    Overview

    This article explains how to change the signing certificate algorithm for a SecureAuth CloudEntity Workspace's OAuth tokens, choosing between RSA and Elliptic Curve Digital Signature Algorithm (ECDSA).

     

    Change the Signing Certificate Algorithm

    1. Sign in to CloudEntity and, in the correct Workspace, go to OAuth > Tokens > Signing and Encryption.
    2. Scroll down to Signing key rotation settings.
    3. Under Manual key rotation, select Rotate key.

      The Signing key rotation settings panel for a CloudEntity Workspace, showing Automatic key rotation as Inactive and a Manual key rotation panel with Rotate key and Rotate and revoke key buttons, plus the current and next-in-queue valid keys.

      This action cannot be undone. Once you confirm the rotation, the current signing key is replaced by the next key in queue, and a new key with the algorithm you select becomes the next key in queue. Any Service Provider still using the previous signing key's public key will need to be updated.

    4. In the Rotate Signing Keys dialog, under Select the token signing algorithm type, choose RSA or ECDSA for the new key.
    5. Select Rotate keys to confirm.

      The Rotate Signing Keys confirmation dialog, with RSA and ECDSA algorithm options, a warning that the action cannot be undone, and a Rotate keys button.

    The key that was previously Next key in queue becomes the Current key in use, and the newly created key, with the algorithm you selected, becomes the new Next key in queue.

    The Signing key rotation settings panel after rotation, showing the RSA key that was previously next in queue now listed as the current key in use, and a newly created EC key listed as the next key in queue.

    For more information, see CloudEntity's Signing Keys Management documentation.


     

    Special Considerations

    Rotating a signing key cannot be undone. Confirm that every Service Provider using the current signing key's public key is ready to pick up the new key before you rotate, since tokens signed with a revoked key will no longer validate.


     

    SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.

    Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.

    0 out of 0 found this helpful

    Comments

    0 comments

    Please sign in to leave a comment.