3 ms·
You only need a cryptographically secure RNG to generate a key pair. Assuming asymetric keys. That private key can then be used to sign many many JWTS. Wherea
by diroussel 4y ago
You only need a cryptographically secure RNG to generate a key pair. Assuming asymetric keys. That private key can then be used to sign many many JWTS.
Whereas generating new session ids will always need fresh entropy.
- dontlaugh 4y agoThat depends on the algorithm, some depend on randomness like IVs.