<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0cm;
        line-height:110%;
        font-size:11.5pt;
        font-family:"Calibri",sans-serif;
        mso-fareast-language:EN-US;}
span.E-MailFormatvorlage24
        {mso-style-type:personal-compose;
        font-family:"Calibri",sans-serif;
        color:windowtext;
        font-weight:normal;
        font-style:normal;}
.MsoChpDefault
        {mso-style-type:export-only;
        mso-ligatures:none;
        mso-fareast-language:EN-US;}
@page WordSection1
        {size:612.0pt 792.0pt;
        margin:70.85pt 70.85pt 2.0cm 70.85pt;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="DE-AT" link="#00587A" vlink="#009C9B" style="word-wrap:break-word">
<div class="WordSection1">
<p class="MsoNormal">Hi!<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><span lang="EN-US">We would prefer to use a replicated in-memory storage system instead of the DataSealer/AES-encryption mechanism for ensuring clustering-capability of the OIDC OP functionality (nodes need to read the OIDC authorization
 codes of other nodes), for security/performance reasons (file-based key storage doesn’t fit our security requirements, HSM-based crypto was used so far but we have load issues…<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US"><o:p> </o:p></span></p>
<p class="MsoNormal"><span lang="EN-US">The OIDC OP plugin seems to allow to replace the default DataSealer bean shibboleth.oidc.TokenSealer with a custom one (with the idp.oidc.tokenSealer property), so the idea is to extend net.shibboleth.shared.security.DataSealer
 and overwrite the wrap/unwrap methods with a custom implementation that writes/reads the data to a replicated in-memory storage instead of encrypting/decrypting it.<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US">We assume this should work (does it?), BUT: We discovered the comment “TODO: make final” in net.shibboleth.shared.security.DataSealer – are there plans to introduce an interface or something like that to be able to replace
 the default DataSealer in the future, or is the plan to stop allowing customization of this functionality?<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US"><o:p> </o:p></span></p>
<p class="MsoNormal"><span lang="EN-US">Is there a better/more correct solution for our issue?<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US"><o:p> </o:p></span></p>
<p class="MsoNormal"><span lang="EN-US">Thanks in advance & best regards,<o:p></o:p></span></p>
<p class="MsoNormal" style="line-height:normal"><span style="font-size:11.0pt;mso-fareast-language:DE-AT"><o:p> </o:p></span></p>
<p class="MsoNormal" style="line-height:normal"><span style="font-size:11.0pt;mso-fareast-language:DE-AT">Mathias Bachl
<o:p></o:p></span></p>
</div>
</body>
</html>