Brock 8/9/2019

IdentityServer and Signing Key Rotation

Read Original

This technical article details the security best practice of periodically rotating cryptographic signing keys in IdentityServer. It explains the process using AddSigningCredential for the active key and AddValidationKey for pre-active or retired keys, ensuring a smooth transition to avoid validation failures in client caches during key rotation.

IdentityServer and Signing Key Rotation

Comments

No comments yet

Be the first to share your thoughts!

Browser Extension

Get instant access to AllDevBlogs from your browser

Top of the Week