Skip to Main Content
Integration


This is an IBM Automation portal for Integration products. To view all of your ideas submitted to IBM, create and manage groups of Ideas, or create an idea explicitly set to be either visible by all (public) or visible only to you and IBM (private), use the IBM Unified Ideas Portal (https://ideas.ibm.com).


Shape the future of IBM!

We invite you to shape the future of IBM, including product roadmaps, by submitting ideas that matter to you the most. Here's how it works:

Search existing ideas

Start by searching and reviewing ideas and requests to enhance a product or service. Take a look at ideas others have posted, and add a comment, vote, or subscribe to updates on them if they matter to you. If you can't find what you are looking for,

Post your ideas
  1. Post an idea.

  2. Get feedback from the IBM team and other customers to refine your idea.

  3. Follow the idea through the IBM Ideas process.


Specific links you will want to bookmark for future use

Welcome to the IBM Ideas Portal (https://www.ibm.com/ideas) - Use this site to find out additional information and details about the IBM Ideas process and statuses.

IBM Unified Ideas Portal (https://ideas.ibm.com) - Use this site to view all of your ideas, create new ideas for any IBM product, or search for ideas across all of IBM.

ideasibm@us.ibm.com - Use this email to suggest enhancements to the Ideas process or request help from IBM for submitting your Ideas.


Status Delivered
Workspace DataPower Gateway
Created by Guest
Created on Jan 21, 2020

Support numeric value in Registered claim 'iat' in JOSE DataPower library

The IBM DataPower JOSE library does not support numeric values for registered claim ‘iat' according to the spec.
We are required to use ‘iat' during Message encryption which uses a JSON Web Token (this must be a JSON number representing the number of seconds from 1970-01-01T0:0:0Z as measured in GMT until the date/time) for encrypting the message during the external communication. There are various claims in the JWT protected header and one of them is ‘iat' and it needs to be set to numeric value and JWT spec clearly mention that as well . https://tools.ietf.org/html/rfc7519#section-4.1.6 Unfortunately, DataPower does not support numeric value in ‘iat.

If a numeric value is supplied - the JOSE library throws an error when parsing it : mpgw (JWS-Encryption): request POC0JWS_Encrypt_JWE #2 gatewayscript: Transforming the content of INPUT. The transformation local:///JWE_Encrypt.js is applied. The results are stored in PIPE. failed: jwe-encrypt error: TypeError: Invalid type 'number (1579623770)' detected on method invocation. Method name: setProtected; Parameter index: 1; Expected type: string): jwe-encrypt error: TypeError: Invalid type 'number (1578983321)' detected on method invocation. Method name: setProtected; Parameter index: 1; Expected type: string (from client).

Similar issue with other element called http://openbanking.org.uk/iat was fixed under the RFE https://www.ibm.com/developerworks/rfe/execute?use_case=viewRfe&CR_ID=131757
We request the similar fix for ‘iat' claim as well, so that we can continue to use IBM DataPower gateway for all encryption and decryption requirements.

Idea priority Urgent
RFE ID 139583
RFE URL
RFE Product IBM DataPower Gateways