Getting a grasp on Heartbleed and IDPs

Wessel, Keith kwessel at illinois.edu
Thu Apr 10 14:02:03 EDT 2014


Thanks so much, Ian, Scott, and others for all the helpful info.

Our security folks are breathing a bit easier now.

And Scott, good suggestion on separate TLS and signing certs.

Keith


From: users-bounces at shibboleth.net [mailto:users-bounces at shibboleth.net] On Behalf Of Ian Young
Sent: Thursday, April 10, 2014 11:36 AM
To: Shib Users
Subject: Re: Getting a grasp on Heartbleed and IDPs


On 10 Apr 2014, at 17:29, Wessel, Keith <kwessel at illinois.edu<mailto:kwessel at illinois.edu>> wrote:


Thanks for the further info, Ian. What's the lifetime of the transient session key?

I would expect the session key to be a different random bit string for every encrypted message.

               -- Ian



-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20140410/fba2045a/attachment.html 


More information about the users mailing list