JsonWebKeyExtensions Class
Provides extension methods for the JsonWebKey model to simplify the process of populating its properties from different sources. These methods enable easy conversion between JsonWebKey and various cryptographic representations.
public static class JsonWebKeyExtensionsInheritance System.Object → JsonWebKeyExtensions
Fields
JsonWebKeyExtensions.MinimumRsaKeyBits Field
The smallest RSA modulus RFC 7518 permits. Four sections state it, one per family: Section 3.3 and Section 3.5 for signing, Section 4.2 and Section 4.3 for key encryption. Almost the same words - 3.3 and 4.3 govern several algorithms and say "these", 3.5 and 4.2 govern one and say "this". One number here, so the sites that enforce it cannot drift apart.
public const int MinimumRsaKeyBits = 2048;Field Value
Methods
JsonWebKeyExtensions.Apply(this EllipticCurveJsonWebKey, ECParameters) Method
Applies Elliptic Curve parameters to an EllipticCurveJsonWebKey.
public static Abblix.Jwt.EllipticCurveJsonWebKey Apply(this Abblix.Jwt.EllipticCurveJsonWebKey jwk, System.Security.Cryptography.ECParameters parameters);Parameters
jwk EllipticCurveJsonWebKey
The EllipticCurveJsonWebKey to which the EC parameters are to be applied.
parameters System.Security.Cryptography.ECParameters
The ECParameters providing the Elliptic Curve key information.
Returns
EllipticCurveJsonWebKey
The updated EllipticCurveJsonWebKey with applied Elliptic Curve parameters.
JsonWebKeyExtensions.Apply(this RsaJsonWebKey, RSAParameters) Method
Applies RSA parameters to an RsaJsonWebKey.
public static Abblix.Jwt.RsaJsonWebKey Apply(this Abblix.Jwt.RsaJsonWebKey jwk, System.Security.Cryptography.RSAParameters parameters);Parameters
jwk RsaJsonWebKey
The RsaJsonWebKey to which the RSA parameters are to be applied.
parameters System.Security.Cryptography.RSAParameters
The RSAParameters providing the RSA key information.
Returns
RsaJsonWebKey
The updated RsaJsonWebKey with applied RSA parameters.
JsonWebKeyExtensions.Apply<T>(this T, X509Certificate2) Method
Applies X509Certificate2 properties to a JsonWebKey.
public static T Apply<T>(this T jwk, System.Security.Cryptography.X509Certificates.X509Certificate2 certificate)
where T : Abblix.Jwt.JsonWebKey;Type parameters
T
The type of JsonWebKey (must be a subclass).
Parameters
jwk T
The JsonWebKey to which the certificate properties are to be applied.
certificate System.Security.Cryptography.X509Certificates.X509Certificate2
The X509Certificate2 providing the properties.
Returns
T
The updated JsonWebKey with applied certificate properties.
JsonWebKeyExtensions.ModulusBitLength(this RsaJsonWebKey) Method
The real bit length of the key's modulus, ignoring any leading zero octets.
public static int ModulusBitLength(this Abblix.Jwt.RsaJsonWebKey key);Parameters
key RsaJsonWebKey
Returns
Remarks
RSA.KeySize is not this number, and how far it differs depends on the platform. It reports
the key as the importer built it: Windows CNG keeps a left-padded modulus at its padded length and
reports twice the real strength, while Linux (OpenSSL) strips the leading zeros and reports the
true one. So a size check written against that property refuses a downgraded key on one operating
system and admits it on another - which is a worse failure than either, because the deployment
that admits it looks identical to the one that does not, and the forgery arrives later from
whoever factored the real modulus.
Measuring the modulus itself removes the platform from the question. It is also never larger than
RSA.KeySize, so switching to it can only add refusals, never remove one.
RFC 7518 Section 2 requires the minimal encoding - "The octet sequence MUST utilize the minimum number of octets needed to represent the value" - which is what this measurement follows. Padding far enough to matter is NOT something a library does by accident: the one benign quirk the specification records is a single extra zero octet (Section 6.3.1.1, "returning 257 octets for a 2048-bit key"), and one octet moves neither check in either direction. Sixty-four of them is a malformed or hostile JWKS entry.
The leading octet contributes only the bits from its own highest set bit down, which is what makes this the modulus's true length rather than a rounded-up octet count.
JsonWebKeyExtensions.RsaSectionFor(string) Method
The RFC 7518 section that carries the key-size requirement for algorithm.
public static string RsaSectionFor(string algorithm);Parameters
algorithm System.String
Returns
Exceptions
System.ArgumentException
The algorithm is not one this library enforces a floor for.
Remarks
A refusal has to send the operator to the paragraph that refused them. Sections 3 and 4 are container headings and state no size requirement at all, so citing either leaves the reader looking at a table of algorithm names and no MUST - which reads as the library inventing the rule.
JsonWebKeyExtensions.RsaSectionForOrNothing(string) Method
The WHOLE citation phrase, ready to drop into a refusal message - "per RFC 7518 Section 3.3", or "for RSA signatures" when the algorithm has no section of its own.
public static string RsaSectionForOrNothing(string algorithm);Parameters
algorithm System.String
Returns
Remarks
Two differences from RsaSectionFor(string), and both matter at a call site. This one never
throws, because an unknown algorithm must not replace the refusal the operator was about to read
with a complaint about the citation - and it is reachable, since an RSA key carrying no
alg resolves to SigningAlgorithms.None. And this one carries the words "per RFC
7518" itself, where RsaSectionFor(string) returns the bare section and leaves them to the
caller. Interpolate this one into a sentence that writes them too and the message says them twice.
JsonWebKeyExtensions.SupportsAlgorithm(this JsonWebKey, string) Method
Whether this key can carry out the given algorithm - JWS signing or JWE key management - judged by the key's own material rather than by what it declares.
public static bool SupportsAlgorithm(this Abblix.Jwt.JsonWebKey key, string algorithm);Parameters
key JsonWebKey
The key to test.
algorithm System.String
The JWS algorithm the caller needs.
Returns
System.Boolean
True when the key's type, and for ECDSA its curve, match what the algorithm requires.
Remarks
RFC 7517 section 4.4 makes alg OPTIONAL, so a key may simply not say what it is for - and a key
imported from a certificate never does. Such a key is not "unknown", it is answerable: RFC 7518 section 3.1
binds each algorithm to a key type, and section 3.4 binds each ECDSA algorithm to one curve. Asking the
material is therefore exact, and it is the only question that matters at the point of use, since a
declaration is a claim while the material is the fact.
JsonWebKeyExtensions.ToEcdh(this EllipticCurveJsonWebKey) Method
Converts an EllipticCurveJsonWebKey to an ECDiffieHellman object for ECDH key agreement operations (e.g. the ECDH-ES family of JWE key management algorithms).
public static System.Security.Cryptography.ECDiffieHellman ToEcdh(this Abblix.Jwt.EllipticCurveJsonWebKey key);Parameters
key EllipticCurveJsonWebKey
The EllipticCurveJsonWebKey to be converted.
Returns
System.Security.Cryptography.ECDiffieHellman
An ECDiffieHellman object based on the provided EllipticCurveJsonWebKey.
JsonWebKeyExtensions.ToEcdsa(this EllipticCurveJsonWebKey) Method
Converts an EllipticCurveJsonWebKey to an ECDsa object, which represents an ECDSA public and private key pair or just a public key.
public static System.Security.Cryptography.ECDsa ToEcdsa(this Abblix.Jwt.EllipticCurveJsonWebKey key);Parameters
key EllipticCurveJsonWebKey
The EllipticCurveJsonWebKey to be converted.
Returns
System.Security.Cryptography.ECDsa
An ECDsa object based on the provided EllipticCurveJsonWebKey.
JsonWebKeyExtensions.ToEcParameters(this EllipticCurveJsonWebKey) Method
Converts an EllipticCurveJsonWebKey to ECParameters, which represent the key parameters used in ECDSA cryptographic operations. Supports P-256, P-384, and P-521 curves as defined in NIST standards.
public static System.Security.Cryptography.ECParameters ToEcParameters(this Abblix.Jwt.EllipticCurveJsonWebKey key);Parameters
key EllipticCurveJsonWebKey
The EllipticCurveJsonWebKey to be converted.
Returns
System.Security.Cryptography.ECParameters
An ECParameters object based on the provided EllipticCurveJsonWebKey.
Exceptions
System.InvalidOperationException
Thrown when the curve type is not supported.
JsonWebKeyExtensions.ToJsonWebKey(this X509Certificate2, bool) Method
Converts an X509Certificate2 to a JsonWebKey. The private keys can be optionally included in the conversion.
public static Abblix.Jwt.JsonWebKey ToJsonWebKey(this System.Security.Cryptography.X509Certificates.X509Certificate2 certificate, bool includePrivateKeys=false);Parameters
certificate System.Security.Cryptography.X509Certificates.X509Certificate2
The X509Certificate2 to convert.
includePrivateKeys System.Boolean
Indicates whether to include private keys in the conversion.
Returns
JsonWebKey
A JsonWebKey representing the certificate.
JsonWebKeyExtensions.ToRsa(this RsaJsonWebKey) Method
Converts an RsaJsonWebKey to an RSA object, which represents an RSA public and private key pair or just a public key.
public static System.Security.Cryptography.RSA ToRsa(this Abblix.Jwt.RsaJsonWebKey key);Parameters
key RsaJsonWebKey
The RsaJsonWebKey to be converted.
Returns
System.Security.Cryptography.RSA
An RSA object based on the provided RsaJsonWebKey.
JsonWebKeyExtensions.ToRsaParameters(this RsaJsonWebKey) Method
Converts an RsaJsonWebKey to RSAParameters, which represent the key parameters used in RSA cryptographic operations.
public static System.Security.Cryptography.RSAParameters ToRsaParameters(this Abblix.Jwt.RsaJsonWebKey key);Parameters
key RsaJsonWebKey
The RsaJsonWebKey to be converted.
Returns
System.Security.Cryptography.RSAParameters
An RSAParameters object based on the provided RsaJsonWebKey.