Skip to main content

Signing Keys

  • Purpose: Manage cryptographic keys that sign tokens, assertions, or artifacts consumed by downstream parties to validate authenticity.
  • Step 1: Create a new key and publish its public material (cert/JWK) to relying parties.
  • Step 2: Configure systems to trust both old and new keys for a transition window.
  • Step 3: After confirming adoption, revoke the old key.
  • Step 4: Document change and store the rollout evidence.

Revoke a Key​

  • Immediate removal when compromise is suspected; coordinate with all consuming parties.


Best Practices​

  • Use distinct keys for distinct protocols (SAML signing vs token signing).
  • Plan rotations and communicate dates to downstream teams.
  • Keep rotation scripts and runbooks for incident response.


Troubleshooting​

  • Relying party signature validation fails:
    • Ensure they fetched the updated public key and that clock skew/metadata endpoints are accessible.

Operational Checklist​

  • Publish a JWKS or metadata endpoint so RPs can rotate keys automatically.
  • Keep a record of all key IDs and owners for audits.