Temporarily encrypted user credentials
Karl Gross
grossk79 at gmail.com
Mon Feb 8 12:21:39 EST 2016
Hello!
We're using Shibboleth IdP 3.2.0 and noticed what looks like a temporary
encryption of user credentials in the session persistence backend. They
seem to be reversibly encrypted using a time-bound id-aes128-gcm cipher,
random initialization vector + current master key from JKS storage.
I would like to understand the need for this and if there is a way to turn
if off somewhere in the configuration. They do seem to be purged
automatically after some time but still, why is there a need to store them?
Thanks!
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160208/2827747f/attachment-0001.html>
More information about the users
mailing list