Skip to content

[BUG] How safe is JWT in opensearch #5783

@nnWhisperer

Description

@nnWhisperer

Describe the bug

Hello,
this isn't exactly a bug but not a feature request at all either.
I'm planning to use JWT in production to validate users, rather than username and password and a question came to my mind:
How safe is JWT? Can it be used like a device token? I guess its private key is shared across different users and hence, if so, then, an adversary could leverage this, obtain several jwt signed by the same key and then use cryptographic methods to obtain the key?

Related component

Other

To Reproduce

Just activate JWT authentication, obtain several keys for several users and then use a brute-force approach to obtain the private key

Expected behavior

It should be safer

Additional Details

No response

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingtriagedIssues labeled as 'Triaged' have been reviewed and are deemed actionable.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions