4 ms·
JWT (specifically JWS) is essentially a simplified modern alternative to X.509 certificates and I think it should be perceived in that way. Do we use certifica
by Snawoot 6y ago
JWT (specifically JWS) is essentially a simplified modern alternative to X.509 certificates and I think it should be perceived in that way.
Do we use certificates for authentication? Yes, and it works well.
Do we use certificates for authorization? Not likely. Instead, usually we ensure ID of entity which we communicate with (as result of authentication) and lookup it's permissions in database.
Do we recognize any certificate body as immediate permission requisite? No! Instead, we have signed claim with public key which entity should present in order to prove it's identity (and prove possession of private key later). I. e. we issue end-entity certificate which describes and verifies public key of that entity.
Do we NEED to revoke these end-entity certificates or have them expiring really fast for normal operations like logout? No. There may be something similar to CRL and OCSP for handling emergencies, but this is optional. Instead, we are not trying to handle authorization tasks with authentication mechanism. It's different things. We may just change status for authenticated entity in authorization database. Like: "user:admin;device:XXXXX;status:terminated".
What semantical meaning has revocation/expiration of token issued to alice@example.org? She is no longer alice? I doubt that. She is no longer allowed here? Or her specific device is no longer allowed here? Or her service subscription is just expired? Either way it's not a question for part which recognizes known entities and must work in a "yes" or "no" fashion.
It's not wrong to use JWT for authentication. It's wrong to use ANY authentication for ANY authorization.