How to retrieve the private keys from keycloack realms keys?

Viewed 523

I am trying to get private keys from keycloack realms keys . I am able to get public keys using Open-id/certs api.please let me know if able to get private keys of realms in keycloack.

3 Answers

Well, you are not allowed to. That is why they are called private keys, you can't expect a private key through API.

Private keys are private to the holder, you can learn more about them here.

I am able to get private keys from keycloack database and table name is component_config.

I use the private key, to write tests to tamper the JWT payload to verify an application. I got all securiy pitfalls

Getting private key with MySQL is easy:

use <kc_db_schema>;
SELECT VALUE FROM COMPONENT_CONFIG CC INNER JOIN COMPONENT C INNER JOIN REALM R ON(CC.COMPONENT_ID = C.ID AND R.ID = C.REALM_ID)
WHERE R.NAME='your-realm-name' AND C.NAME = 'rsa-generated' AND CC.name = 'privateKey';

Using this privateKey value I'm able to sign my payload. In Python PyJWT it is VERY important to add the '-----BEGIN RSA PRIVATE KEY-----' / '-----END RSA PRIVATE KEY-----' with linefeeds to the key:

private_key = b"-----BEGIN RSA PRIVATE KEY-----\n<my privateKey from SQL query>\n-----END RSA PRIVATE KEY-----"
jwt_encoded = jwt.encode({my payload}, private_key, algorithm="RS256")
Related