AddTemporarySigningCredential vs AddSigningCredential in IdentityServer4

前端 未结 2 1965
春和景丽
春和景丽 2021-02-19 15:20

According to the docs, IdentityServer uses an asymmetric key pair to sign and validate JWTs. One could either use AddTemporarySigningCredential() in the configurati

2条回答
  •  鱼传尺愫
    2021-02-19 15:52

    The disadvantage is, that every time you restart IdentityServer, the key material will change - or IOW - all tokens that have been signed with the previous key material will fail to validate.

    "Temporary" is really only for situations where you don't have other key material available.

提交回复
热议问题