Temporarily encrypted user credentials

Karl Gross grossk79 at gmail.com
Mon Feb 8 12:21:39 EST 2016


Hello!

We're using Shibboleth IdP 3.2.0 and noticed what looks like a temporary
encryption of user credentials in the session persistence backend. They
seem to be reversibly encrypted using a time-bound id-aes128-gcm cipher,
random initialization vector + current master key from JKS storage.

I would like to understand the need for this and if there is a way to turn
if off somewhere in the configuration. They do seem to be purged
automatically after some time but still, why is there a need to store them?

Thanks!
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160208/2827747f/attachment-0001.html>


More information about the users mailing list