I have implemented an authorization-server application with spring security and using a private key to sign the token. The generated asymmetric key is stored in the resource