njwt icon indicating copy to clipboard operation
njwt copied to clipboard

Why not asymetric crypto?

Open levino opened this issue 9 years ago • 1 comments

I dont get why you rely on a shared secret between SSO server and microservice. Why not use a private Key for the server and the according public key on the microservice?

levino avatar Oct 21 '16 15:10 levino

Hi @Levino , thanks for the question! The choice as actually up to you, this library supports shared keys, or public/private keys. Please take a look at this test to see how to do asymmetric with RSA:

https://github.com/jwtk/njwt/blob/master/test/rsa.js

Please let us know if this is what you're looking for?

robertjd avatar Oct 21 '16 15:10 robertjd