Discussions
Join the NetSuite community to innovate, connect, and discover what’s next.
SuiteWorld brings thousands of innovators, builders, and leaders together to learn, connect, and shape what’s next. This October, explore how to build a stronger foundation for growth through inspiring keynotes, major product reveals, hands-on sessions, and unforgettable moments—all in one place for our biggest event of the year. Register now
End of Exemption for RSA PKCSv1.5 Scheme for OAuth 2.0
This notice applies to customers who have been given an exemption to keep using the RSA PKCSv1.5 scheme in your algorithm for token signing for the OAuth 2.0 client credentials flow. The exemption will end on April 30, 2025. You should update your integrations as soon as possible to make sure they keep working after this day.
What is Changing?
For security reasons, the support is ending for the RSA PKCSv1.5 scheme in algorithms for token signing for the OAuth 2.0 client credentials flow. As of April 30, 2025, exemption to keep using the RSA PKCSv1.5 scheme will end.
Required Actions
Before April 30, 2025, you must update your integrations to use the RSA-PSS scheme. The length of the RSA key must be 3072 bits, or 4096 bits. Alternatively, you can use an EC key instead. The length of the EC key must be 256 bits, 384 bits, or 521 bits.If you use any integrations provided by a third party, you must inform the third party to update the integrations to use the RSSA-PSS scheme, or the EC key. Any integration still using the RSA PKCSv1.5 scheme will stop working after
Regards,
@Robert Nedelkow-Oracle | NetSuite Support Community Administrator
Expand your NetSuite knowledge by joining this month's Ask A Guru Live: PROCURE TO PAY. RSVP for this event now!
