Recovering the REST API signing key
Use this procedure if the REST API JSON Web Token (JWT) signing key is lost or the machine.secrets.enc file is corrupted, but the application encryption key and the databases are intact.
To recover the REST API signing key
- Generate or choose a new signing key of at least 32 characters:
nsscmd -genkey.
- Set the key:
nsscmd -setsecret -configDir "{NSS installation folder}\Config" -name JWT:IssuerSigningKey -value "{new-key}"
- Recycle the IIS application pools, and then restart the Directa Windows service.
- Inform API users that their existing bearer tokens are no longer valid. Clients must obtain new tokens through the authentication endpoint.
Rebuilding machine.secrets.enc
If you are rebuilding the machine.secrets.enc file and you know both the application encryption key and the JWT signing key that you want to use, create a file named machine.secrets.json in the Config folder with the following content:
{
"ApplicationKey": "your-known-application-key",
"JWT": { "IssuerSigningKey": "your-jwt-signing-key-at-least-32-chars" }
}
Then run the following commands:
nsscmd -protectsecrets -configDir "{Config}"
nsscmd -validateconfig -configDir "{Config}"