Reason behind comment in Metadata
Cantor, Scott
cantor.2 at osu.edu
Wed Oct 22 17:47:05 EDT 2014
On 10/22/14, 4:41 PM, "Dan McLaughlin" <dmclaughlin at tech-consortium.com>
wrote:
>Is there a recommended period of time (best practice) for key rollover
>for an SP or IDP?
If you mean how often one should change a key, the answer is that there
are no attacks against RSA that involve quantity of ciphertext. In other
words, there is no specific time frame in which it is rational to incur
the expense of a key change in most cases, you do it when you have to.
The point of metadata is to make it possible to automate, and to handle
revocation events (the metadata is simply an anti-CRL), but not to make it
frequent. Very few non-Shibboleth implementations support this, so people
changing keys have a massive chore in front of them anyway.
-- Scott
More information about the dev
mailing list