IdentityServer 3 signing certificate expiry

Viewed 1503

What happens when the signing certificate (used for signing jwt tokens) expires when using IdentityServer 3?

It's unclear to me and I can't find any documentation, other than that it's possible to get a warning that it has expired. (Ref. https://identityserver.github.io/Documentation/docsv2/configuration/events.html)

Is there any mechanism that stops the use of expired signing certs?
And what happens on the client side (client being the Web API that uses IdentityServer for authentication) when validating a token signed by an expired certificate? (For example if https://github.com/IdentityServer/IdentityServer3.AccessTokenValidation is used as a middleware.)

2 Answers

Disclaimer: I never worked with IdentityServer3

The outside world doesn't know your certificate and therefore doesn't know it's expired. The outside world merely sees your public key at:

YourIdentityServer.com/.well-known/openid-configuration

or more accurately:

YourIdentityServer.com/.well-known/openid-configuration/jwks

You can play around with this: Create a new cert on startup (see https://gist.github.com/mykeels/408a26fb9411aff8fb7506f53c77c57a). Even if you set the TimeSpan to one minute, it will keep working.

But once you wait 1 minute and restart your IdentityServer your token from last sign in will be considered invalid, because it was created with the now outdated signing key. It is checked against the new public key and fails.

It seems to be recommended to periodically replace your cert with a new one, while also keeping the previous key around, see "signing key rollover": https://docs.identityserver.io/en/dev/topics/crypto.html#signing-key-rollover

Related