Zum Hauptinhalt springen
tsecurity.de LIVE
Echtzeit-Radar & Feeds
Alle RSS Feeds
👥 Community & Social
IT Security Toolsboha v0.20.2(20.09.2026 um 16:32 Uhr)
IT Security Toolscyberbro v0.15.0(20.09.2026 um 17:32 Uhr)
IT Security NachrichtenUS, China seek Xi-Trump summit deliverables in New York talks(20.09.2026 um 16:34 Uhr)
Sicherheitslücken (CVE)Gyazo Server Vulnerability Targeted to Steal Millions of User Records(20.09.2026 um 17:02 Uhr)
IT Security NachrichtenHearth and Hamlet Review (PC)(20.09.2026 um 16:40 Uhr)
IT Security NachrichtenKI knackt Weltkriegs-Funkspruch - Historiker irrten sich 108 Jahre lang(20.09.2026 um 16:41 Uhr)
IT Security Toolsboha v0.20.2(20.09.2026 um 16:32 Uhr)
IT Security Toolscyberbro v0.15.0(20.09.2026 um 17:32 Uhr)
IT Security NachrichtenUS, China seek Xi-Trump summit deliverables in New York talks(20.09.2026 um 16:34 Uhr)
Sicherheitslücken (CVE)Gyazo Server Vulnerability Targeted to Steal Millions of User Records(20.09.2026 um 17:02 Uhr)
IT Security NachrichtenHearth and Hamlet Review (PC)(20.09.2026 um 16:40 Uhr)
IT Security NachrichtenKI knackt Weltkriegs-Funkspruch - Historiker irrten sich 108 Jahre lang(20.09.2026 um 16:41 Uhr)
Intelligence View
⚡ tsecurity.de Intelligence

JWT Validation Against an RSA Public Key: The ValidAlgorithms Gotcha

Reagiere als Erste:r — dein Feedback zählt!

If you're validating JWTs signed with RSA in .NET and getting a signature validation failure even though you're certain the public key is correct, there's a good chance the problem isn't your key at all — it's how you've configured ValidAlgorithms.

The symptom

You set up token validation like this:

var validationParameters = new TokenValidationParameters
{
    ValidateIssuerSigningKey = true,
    IssuerSigningKey = rsaSecurityKey,
    ValidAlgorithms = new[] { "RS256" },
    // ...other parameters
};

The public key is correct. You've verified it against the signing certificate. And yet token validation still fails with a signature error, as if the key were wrong.

The wrong assumption

The natural assumption is that "RS256" is "RS256" — a single, standard algorithm identifier that any RSA-signed JWT will use, and any validator will recognize.

Not every token issuer sends that identifier in the same format.

The actual cause

Some identity providers — particularly older or WCF-based token services — express the signing algorithm as a full URI rather than the short JWT-standard name. Instead of "RS256", the token's header may specify something like "http://www.w3.org/2001/04/xmldsig-more#rsa-sha256". If your ValidAlgorithms list only contains the short-form name, tokens signed with the URI-form algorithm identifier get rejected outright — even though the actual cryptographic signature is completely valid.

The fix

Include both the short-form and URI-form algorithm identifiers in ValidAlgorithms:

var validationParameters = new TokenValidationParameters
{
    ValidateIssuerSigningKey = true,
    IssuerSigningKey = rsaSecurityKey,
    ValidAlgorithms = new[]
    {
        "RS256",
        "http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"
    },
    // ...other parameters
};

Once both forms are present, tokens get validated correctly regardless of which identifier format the issuing service used to describe its signing algorithm.

The broader lesson

If you're integrating JWT validation with an identity provider you don't fully control — especially anything with roots in WCF or older enterprise SSO systems — don't assume the algorithm identifier will always arrive in the modern short form. Check the actual token header (a JWT decoder makes this trivial) before assuming your key or your validation logic is at fault. A "signature invalid" error can be entirely about algorithm identifier mismatch, with the signature itself being perfectly fine.

Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten JWT Validation Against an RSA Public Key: The ValidAlgorithms Gotcha

Thematisch verwandte Begriffe: Validation, Against, Public, ValidAlgorithms · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-93956 | A flaw has been found in olivier-ls PHP-FTS up to 1.1.2. Affected by thi…
Advisory →
TTS Reader • tsecurity.de Voice
tsecurity.de Icon
tsecurity.de App
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
🔖 Gespeicherte Artikel
📂 Keine gespeicherten Artikel vorhanden.
Zurück Ziehen Vor
Links: vorheriger Artikel Rechts: nächster Artikel unten: schließen
News NIS-2 Frühwarnung Tier-1 Intel ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...

Zurück: vorheriger Vor: nächster
↗ Original-Quelle
Social Reaktionen Deine Reaktion zählt
Einstufung & Relevanz-Poll 0 Stimmen
In sozialen Netzwerken teilen 1-Klick