Hacktoberfest 2026: die Issues, die Maintainer für den Oktober markiert haben – offen und einsteigerfreundlich. Hacktoberfest-Issues durchsuchen

ECDSA (ES256) support issues in OIDC module (JWK generation and token verification)

Offen
#334 1 Kommentar 0 Reaktionen 1 zugewiesene Person Auf GitHub ansehen

@cicnavi arbeitet bereits daran.

Seit 15.4.2026.

Bewertung

Dieses Issue wurde noch nicht bewertet.

Beschreibung

prepared

Hi,

I am currently working with the SimpleSAMLphp OIDC module and trying to use ECDSA (ES256) for signing tokens instead of RSA.

I encountered multiple issues that seem to indicate incomplete or inconsistent support for ECDSA.


1. JWK generation issue

In JsonWebKeySetService::prepareProtocolJwkSet(), the implementation uses:

JWKFactory::createFromKeyFile($certificatePath, ...)

However, $certificatePath points to an X.509 certificate file (.crt), not a private key.

According to the JWT Framework documentation, createFromKeyFile() expects a key file, while certificates should be loaded using:

JWKFactory::createFromCertificateFile()

This mismatch causes failures when using ECDSA certificates, while RSA may work by coincidence.


2. Access token verification issue

In BearerTokenValidator, the signer is hardcoded to RSA:

use Lcobucci\JWT\Signer\Rsa\Sha256;

Configuration::forSymmetricSigner(...)

This causes ES256 tokens to fail verification with:

Access token could not be verified

The validator should dynamically select the signer based on the token's alg header (e.g., ES256 vs RS256), and use forAsymmetricSigner().


3. Expected behavior
  • The module should support both RS256 and ES256
  • JWK generation should correctly use certificate-based loading
  • Token verification should dynamically select the correct signer

4. Questions
  1. Is ECDSA (ES256) officially supported by this module?
  2. If yes, what is the correct way to configure keys and certificates?
  3. Should certificates be combined with private keys, or kept separate?
  4. Is there a recommended key generation procedure?

5. Suggested fixes
  • Replace createFromKeyFile() with createFromCertificateFile() when loading certificates
  • Refactor BearerTokenValidator to support multiple algorithms (RS256, ES256)

Any guidance would be greatly appreciated.

Thanks!

Vorherrschende Sprache
PHP
Sterne
50
Forks
28
Ø Merge
1 Min.
Gemergte PRs (30 T.)
1

Entwicklungsumgebung

Dieses Projekt bietet weder Dev-Container noch Dockerfile noch Beitragsleitfaden – die Einrichtung liegt bei Ihnen. Beginnen Sie mit der README; die allgemeinen Schritte stehen in unserem Leitfaden für den ersten Beitrag.

Erste Schritte

  1. Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
  2. Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
  3. Forken Sie das Repository und arbeiten Sie in einem Branch.
  4. Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.

Mehr aus simplesamlphp/simplesamlphp-module-oidc

Alle Issues in simplesamlphp/simplesamlphp-module-oidc

Ähnliche Issues

Weitere Issues zu PHP

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.