I am wondering about how Kong manages critical security information such as encryption keys. Plugins such as JWT stores OAuth2 Client Secrets, for example, will need a secured storage for that to support various security requirements such as HIPPA and PCI, right?
Related topics
| Topic | Replies | Views | Activity | |
|---|---|---|---|---|
| How to get jwt_secrets when having consumer_id | 0 | 387 | April 11, 2019 | |
| 🦍 2/28 API Secrets Management: Integrating Kong Gateway with Your Identity Manager [User Call] | 0 | 348 | January 26, 2023 | |
| Use p12 instead of rsa_public_key for jwt plugin | 1 | 639 | November 12, 2020 | |
| OAuth Access Token with AES Encryption | 0 | 406 | April 25, 2023 | |
| JWT plugin and key lookup using the token's kid value | 0 | 430 | April 15, 2021 |