Uploaded image for project: 'Core Server'
  1. Core Server
  2. SERVER-91657

Implement JWK Expiration

    • Type: Icon: Task Task
    • Resolution: Unresolved
    • Priority: Icon: Major - P3 Major - P3
    • None
    • Affects Version/s: None
    • Component/s: None
    • None
    • Server Security
    • Security 2024-07-22, Security 2024-08-05, Security 2024-08-19

      Create the jwkLifetimeMins server parameter, and use it to set the expiration date on the server-generated JWK keys. Additionally, ensure that we are checking the JWK expiration dates as soon as possible before loading them, and are not using those expired keys to validate tokens.

            Assignee:
            Unassigned Unassigned
            Reporter:
            erin.mcnulty@mongodb.com Erin McNulty
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated: