iya-sts
    Preparing search index...

    A service-provider-side federation relationship's encryption key pair, and the decryption of the encrypted assertions and ID Tokens a partner sends to it.

    Each relationship holds its own key, issued under the realm's Intermediate, sealed where keys persist, rotated with a grace period and published in its metadata or JWKS. Every decryption failure is one code, STS-FED-0138; an algorithm the relationship does not accept is STS-FED-0139. A static utility class that holds no state.

    Index
    RETIRE_JOB: "federation.encryption-key-retire" = RETIRE_JOB

    The id of the scheduler job that removes retired keys.

    ROW_VERSION: 1 = ROW_VERSION

    The key table's row format version; a row of any other is not used.

    SEAL_LABEL: "federation-encryption-key" = SEAL_LABEL

    The keystore label the sealed private keys are counted under.

    • Returns the one sentence every decryption failure is answered with, which deliberately does not say which step failed.

      Returns string

      the sentence

    • Decrypts a compact JWE, an encrypted ID Token, with the relationship's usable keys; the plaintext is the nested JWS, for the caller to verify.

      alg and enc must be the relationship's; a kid selects a key and a kid it does not hold is no key.

      Parameters

      • record: any

        the federation relationship

      • compact: string

        the JWE in compact serialisation

      • OptionalnowMs: number

        the time to check key grace against; now by default

      Returns Decrypted

      { ok: true, plaintext, header, kid, algorithm }, or { ok: false, code, why }

    • Decrypts an XML Encryption element (an EncryptedAssertion, EncryptedID, EncryptedAttribute or WS-Federation EncryptedData) with the relationship's usable keys, accepting only the algorithms it publishes.

      Parameters

      • record: any

        the federation relationship

      • elementXml: string

        the encrypted element, serialised whole

      • OptionalnowMs: number

        the time to check key grace against; now by default

      Returns Decrypted

      { ok: true, xml, kid, algorithm }, or { ok: false, code, why }

    • Returns the SAML metadata KeyDescriptor use="encryption" for the current key, with the encryption methods the relationship accepts.

      Parameters

      • record: any

        the federation relationship

      Returns string

      the XML, or the empty string when there is no current key

    • Returns the key type a key-management algorithm needs: ec-p256 for ECDH, rsa-3072 otherwise.

      Parameters

      • management: string

        the key-management algorithm

      Returns string

      the key type

    • Returns a key row's private key, unsealed where it is sealed: a node KeyObject for a classical row, the parsed AKP JWK for a post-quantum one (#82).

      Parameters

      • record: any

        the federation relationship, for the log line

      • row: any

        the key row

      Returns any

      the key, or null (logged under STS-FED-0137) when it will not open or parse

    • Returns the current key's public JWK with use: enc and the relationship's alg, as /federation/jwks/{id} serves it.

      Parameters

      • record: any

        the federation relationship

      Returns any

      the JWK, or null when there is no current key

    • Registers the retirement scheduler job, once; it runs per realm every five minutes while federation.enabled is on.

      Returns void

    • Removes, in the current realm, every previous key row past its grace period; the scheduler job's body.

      Parameters

      • OptionalnowMs: number

        the time to check against; now by default

      Returns any

      { retired }, how many rows were removed

    • Issues a new encryption key for a relationship, making it current; the key it replaces stays usable for federation.encryptionKeyGraceS.

      Refuses a relationship that decrypts nothing (STS-FED-0144) and a key that could not be issued, sealed or written (STS-FED-0142).

      Parameters

      • id: string

        the relationship id

      • Optionalwhy: string

        the reason recorded with the write

      Returns Promise<any>

      a promise of { ok: true, kid, message } or { ok: false, errors } with its code marked

    • Writes a new encryption key as current, keeping the one it replaces for its grace; sealed where keys persist.

      Parameters

      • id: string

        the relationship

      • record: any

        the relationship's record

      • policy: any

        its encryption policy

      • made: any

        the key: kid, publicJwk, privateKey, certificate or kem

      • Optionalwhy: string

        the audit sentence

      Returns Promise<any>

      { ok, kid, message } or { ok: false, errors }

    • Returns the key rows that may decrypt now: the current key and a previous one still inside its grace period, current first.

      Parameters

      • record: any

        the federation relationship

      • OptionalnowMs: number

        the time to check against, in milliseconds; now by default

      Returns any[]

      the rows

    • Returns what the relationship page and GET /admin-api/federation show of its encryption: the policy, the public key table and the current certificate as PEM, never a private key.

      Parameters

      • record: any

        the federation relationship

      Returns any

      the view, or null for a relationship that decrypts nothing