为什么我可以使用EC-Key-Key-Pairs使用RSA-AlgorithM签名和验证JWT?
我在Node.js中使用加密核心模块来生成EC-KEYP。
然后,我使用此密钥对签名和验证JWT。
我希望签名/验证仅在使用EC-Algorithm时起作用。
但是,除了HMAC以外,它似乎正在使用任何算法。
从我的理解来看,这是不可能的。
有人可以向我解释一下吗?
感谢您阅读我的问题。
const crypto = require('crypto')
const jwt = require('jsonwebtoken')
const keyPair = crypto.generateKeyPairSync('ec', {
namedCurve: 'secp256k1',
publicKeyEncoding: {
type: 'spki',
format: 'pem'
},
privateKeyEncoding: {
type: 'pkcs8',
format: 'pem'
}
})
const token = jwt.sign({}, keyPair.privateKey, {
algorithm: 'ES256' // I expect this to work, but it seems to be also working with e.g. "RS256" or "PS512", which I don't understand.
})
const verify = jwt.verify(token, keyPair.publicKey)
I use the crypto core-module in node.js to generate an EC-key-pair.
I then use this key-pair to sign and verify JWT's.
I would expect the signing/verification to only work when using an EC-algorithm.
However it seems to be working with any algorithm except HMAC.
From my understanding, this shouldn't be possible.
Can anyone explain this to me?
Thank you for reading my question.
const crypto = require('crypto')
const jwt = require('jsonwebtoken')
const keyPair = crypto.generateKeyPairSync('ec', {
namedCurve: 'secp256k1',
publicKeyEncoding: {
type: 'spki',
format: 'pem'
},
privateKeyEncoding: {
type: 'pkcs8',
format: 'pem'
}
})
const token = jwt.sign({}, keyPair.privateKey, {
algorithm: 'ES256' // I expect this to work, but it seems to be also working with e.g. "RS256" or "PS512", which I don't understand.
})
const verify = jwt.verify(token, keyPair.publicKey)
如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。
data:image/s3,"s3://crabby-images/d5906/d59060df4059a6cc364216c4d63ceec29ef7fe66" alt="扫码二维码加入Web技术交流群"
绑定邮箱获取回复消息
由于您还没有绑定你的真实邮箱,如果其他用户或者作者回复了您的评论,将不能在第一时间通知您!
发布评论
评论(1)
这也让我很好奇,所以我试图挖掘来源。
如果您遵循签署JWT期间发生的事情,最终将到达这个:
这不会回答原因。因此,更深入地挖掘
加密
在C中实现,我认为这是相关部分。如果我正确理解,那么它起作用的原因主要取决于它只是将其读为字符串/缓冲区。This made me curious too, so I tried to dig up sources.
If you follow what happens during signing a jwt, you will eventually get to this:
This doesn't answer why though. So digging deeper,
crypto
is implemented in C, and I think this is the relevant part. If I understand correctly, the reason it works mostly comes down to the fact that it is just read as a string/buffer.