DataSealer dependencies

Cantor, Scott cantor.2 at osu.edu
Mon Mar 7 21:45:05 EST 2016


On 3/7/16, 9:22 PM, "users on behalf of Paul B. Henson" <users-bounces at shibboleth.net on behalf of henson at cpp.edu> wrote:


>
>I'm using server-side storage for sessions, and the StoredTransientIdGenerator, which takes care of the first two deps. I'm not sure about the third use case? How does that use the data sealer key exactly?

If you set the option to save passwords in the authentication results. The password is stored in a Principal object but it's encrypted when it's stored in the session "at rest".

> For now, I guess I need to keep it around just so the idp will run :). But do I need to rotate it for security purposes? Do I need to replicate it between cluster members?

Only if it's used for something.

-- Scott



More information about the users mailing list