<style>
/* Changing the layout to use less space for mobiles */
@media screen and (max-device-width: 480px), screen and (-webkit-min-device-pixel-ratio: 2) {
    #email-body { min-width: 30em !important; }
    #email-page { padding: 8px !important; }
    #email-banner { padding: 8px 8px 0 8px !important; }
    #email-avatar { margin: 1px 8px 8px 0 !important; padding: 0 !important; }
    #email-fields { padding: 0 8px 8px 8px !important; }
    #email-gutter { width: 0 !important; }
}
</style>
<div id="email-body">
<table id="email-wrap" align="center" border="0" cellpadding="0" cellspacing="0" style="background-color:#f0f0f0;color:#000000;width:100%;">
    <tr valign="top">
        <td id="email-page" style="padding:16px !important;">
            <table align="center" border="0" cellpadding="0" cellspacing="0" style="background-color:#ffffff;border:1px solid #bbbbbb;color:#000000;width:100%;">
                <tr valign="top">
                    <td bgcolor="#ffffff" style="background-color:#ffffff;color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;line-height:1;"><img src="https://shibboleth.net/images/shib_240x83.png" alt="" style="vertical-align:top;" /></td>
                </tr><tr valign="top">
    <td id="email-banner" style="padding:32px 32px 0 32px;">

                
        
        
            <table align="left" border="0" cellpadding="0" cellspacing="0" width="100%" style="width:100%;">
    <tr valign="top">
        <td style="color:#505050;font-family:Arial,FreeSans,Helvetica,sans-serif;padding:0;">
                                        <img id="email-avatar" src="https://issues.shibboleth.net/jira/secure/useravatar?ownerId=ian%40iay.org.uk&avatarId=10125" alt="" height="48" width="48" border="0" align="left" style="padding:0;margin: 0 16px 16px 0;" />
                        <div id="email-action" style="padding: 0 0 8px 0;font-size:12px;line-height:18px;">
                                    <a class="user-hover" rel="ian@iay.org.uk" id="email_ian@iay.org.uk" href="https://issues.shibboleth.net/jira/secure/ViewProfile.jspa?name=ian%40iay.org.uk" style="color:#326ca6;">Ian Young</a>
     commented on <img src="https://issues.shibboleth.net/jira/images/icons/issuetypes/bug.png" height="16" width="16" border="0" align="absmiddle" alt="Bug"> <a style='color:#326ca6;text-decoration:none;' href='https://issues.shibboleth.net/jira/browse/IDP-616'>IDP-616</a>
            </div>
                        <div id="email-summary" style="font-size:16px;line-height:20px;padding:2px 0 16px 0;">
                <a style='color:#326ca6;text-decoration:none;' href='https://issues.shibboleth.net/jira/browse/IDP-616'><strong>lack of active changes to consent causes premature expiry and re-prompting</strong></a>
            </div>
                    </td>
    </tr>
</table>
    </td>
</tr>
<tr valign="top">
    <td id="email-fields" style="padding:0 32px 32px 32px;">
        <table border="0" cellpadding="0" cellspacing="0" style="padding:0;text-align:left;width:100%;" width="100%">
            <tr valign="top">
                <td id="email-gutter" style="width:64px;white-space:nowrap;"></td>
                <td>
                    <table border="0" cellpadding="0" cellspacing="0" width="100%">
                        <tr valign="top">
    <td colspan="2" style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 0 16px 0;width:100%;">
        <div class="comment-block" style="background-color:#edf5ff;border:1px solid #dddddd;color:#000000;padding:12px;"><p>I have built a snapshot and updated my IdP. Short summary: issue appears to be fixed. New behaviour is that the cookie is rewritten if a newer key is available, so that as long as you log in again before the current key is purged then you'll never be reprompted for consent. If you don't log in for that that period, you'll be reprompted because the key is no longer available. The logging in that latter case is a little scary, so I made a new JIRA case for that (<a href="https://issues.shibboleth.net/jira/browse/IDP-630" title="exception shown if data sealer can&#39;t find expired key">IDP-630</a>).</p>

<p>The cookie was left unchanged if the key hadn't been rolled, as expected.</p>

<p>For reference, the test sequence run with old and new versions of the IdP was:</p>

<ul>
        <li>Clear all IdP cookies</li>
        <li>close and reopen browser, visit an SP</li>
        <li>(prompted for consent)</li>
        <li>close and reopen browser, visit same SP
        <ul>
                <li>old and new: cookie is the same</li>
        </ul>
        </li>
        <li>roll key twice, wait for rollover in logs</li>
        <li>close and reopen browser, visit same SP
        <ul>
                <li>old: cookie is the same</li>
                <li>new: cookie has been rewritten</li>
        </ul>
        </li>
        <li>roll key twice, wait for rollover in logs</li>
        <li>close and reopen browser, visit same SP
        <ul>
                <li>old: reprompted, cookie is rewritten</li>
                <li>new: no prompt, cookie has been rewritten</li>
        </ul>
        </li>
        <li>roll key FOUR times, wait for rollover in logs</li>
        <li>close and reopen browser, visit same SP
        <ul>
                <li>old and new: reprompted, cookie is rewritten</li>
        </ul>
        </li>
</ul>


<p>I think that's enough testing.</p>

<p>In the above, I'm using the default setting for key retention which is 3 generations. The SecretKeyManagement page recommends "<span class="error">&#91;Key rollover&#93;</span> should be done at least daily to limit the chance for, and damage from, exposure."</p>

<p>We probably still need to think about whether those are the right things to recommend. I suspect we should increase the default a bit on the basis that people will probably end up rolling the key daily and a long weekend isn't a good reason to lose persistent settings. Alternatively, we could change our recommendation about frequency of key rolling to weekly if we think that the current recommendation is over-cautious. I'm not sure how one assesses the risk here.</p></div>
        <div style="color:#505050;padding:4px 0 0 0;">                </div>
    </td>
</tr>
                    </table>
                </td>
            </tr>
        </table>
    </td>
</tr>













            </table>
        </td><!-- End #email-page -->
    </tr>
    <tr valign="top">
        <td style="color:#505050;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:10px;line-height:14px;padding: 0 16px 16px 16px;text-align:center;">
            This message is automatically generated by JIRA.<br />
            If you think it was sent incorrectly, please contact your JIRA administrators<br />
            For more information on JIRA, see: <a style='color:#326ca6;' href='http://www.atlassian.com/software/jira'>http://www.atlassian.com/software/jira</a>
        </td>
    </tr>
</table><!-- End #email-wrap -->
</div><!-- End #email-body -->