Skip to content

feat: enable elliptic curve es256 for JWS - #205

Merged
kalinkrustev merged 5 commits into
masterfrom
feat/es256
Jul 4, 2024
Merged

kalinkrustev merged 5 commits into
masterfrom
feat/es256

Conversation

@kalinkrustev

@kalinkrustev kalinkrustev commented Jun 17, 2024 •

Copy link
Copy Markdown
Contributor

Closes #203

  • During signing the algorithm is determined based on the contents of the key file
  • During verification both RS256 and ES256 are allowed.
  • Added a performance test to illustrate the impact.
    The result is available here and shows much better performance when using ES256:
    image

@kalinkrustev kalinkrustev self-assigned this Jun 17, 2024
@kalinkrustev
kalinkrustev marked this pull request as ready for review June 21, 2024 12:26
elnyry-sam-k
elnyry-sam-k previously approved these changes Jul 3, 2024
@elnyry-sam-k

Copy link
Copy Markdown
Member

We have option for both so I'm good for now. We need to continue to use the RS256 on prod / official deployments until the new algorithm is approved by CCB / FSPIOP SIG.

@sonarqubecloud

sonarqubecloud Bot commented Jul 4, 2024

Copy link
Copy Markdown

@kalinkrustev kalinkrustev changed the title Enable elliptic curve es256 for JWS feat: Enable elliptic curve es256 for JWS Jul 4, 2024
@kalinkrustev kalinkrustev changed the title feat: Enable elliptic curve es256 for JWS feat: enable elliptic curve es256 for JWS Jul 4, 2024
@kalinkrustev

Copy link
Copy Markdown
Contributor Author

@elnyry-sam-k , this needs an approval again, as there were merge conflicts and dependency updates

@kalinkrustev
kalinkrustev merged commit ee5036d into master Jul 4, 2024
@kalinkrustev
kalinkrustev deleted the feat/es256 branch July 4, 2024 12:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

The algorithm for JWS is hardcoded to RS256

2 participants