DataSealer dependencies
Cantor, Scott
cantor.2 at osu.edu
Mon Mar 7 21:45:05 EST 2016
On 3/7/16, 9:22 PM, "users on behalf of Paul B. Henson" <users-bounces at shibboleth.net on behalf of henson at cpp.edu> wrote:
>
>I'm using server-side storage for sessions, and the StoredTransientIdGenerator, which takes care of the first two deps. I'm not sure about the third use case? How does that use the data sealer key exactly?
If you set the option to save passwords in the authentication results. The password is stored in a Principal object but it's encrypted when it's stored in the session "at rest".
> For now, I guess I need to keep it around just so the idp will run :). But do I need to rotate it for security purposes? Do I need to replicate it between cluster members?
Only if it's used for something.
-- Scott
More information about the users
mailing list