Is there a risk in using self signed public key for issuing JWT token?

Viewed 549

I have a service that issues tokens to registered clients. Service generates a public key and private key. Stores the private key securely. When a client requests for a token, my service authenticates the client and issues a JWT token which is signed using the private key. My service also publishes the JWKS URI,which has public key info and a public certificate.

Question:

  1. My service is exposing the token and JWKS URI to the internet (https) . What is the risk of exposing the public key and certificate which is self-signed?
2 Answers

Compromised self-signed certificates can pose many security challenges, since attackers can spoof the identity of the victim. Unlike CA-issued certificates, self-signed certificates cannot be revoked. The inability to quickly find and revoke private key associated with a self-signed certificate creates serious risk.

more details here on this link

I think it would depend on the clients who get JWT tokens from your service and if its acceptable for them to use self signed public keys from the JWKS well known endpoint.

I checked Azure AD's JWKs endpoint and even they seem to be using self signed certificates. One of the JWK's x5c value shows below

https://login.microsoftonline.com/common/discovery/v2.0/keys

enter image description here

Btw, x5c or public key is optional in JWKS endpoint so you can also avoid including it in the response if desired.

Related