Cookie Encryption Key
Ramon Pfeiffer
ramon.pfeiffer at uni-tuebingen.de
Tue Jul 18 03:32:50 EDT 2017
Hi all,
I'm planning to set up my IdP in an active-passive clustered
environment. I've stumbled over the Cookie Encryption Key [1] and the
recommendation to regularly recycle it.
For the generation of persistent IDs, I use a
StoredPersistentIdGenerator. I don't want to allow attribute queries via
transient ID.
According to the wiki, I can then disable the use of the cookie
encryption key [2]. Did I miss anything?
Thanks for any help
Ramon Pfeiffer
[1]:
https://wiki.shibboleth.net/confluence/display/IDP30/SecurityAndNetworking#SecurityAndNetworking-CookieEncryptionKey
[2]:
https://wiki.shibboleth.net/confluence/display/IDP30/Disable+use+of+internal+encryption+key
--
Universität Tübingen
Zentrum für Datenverarbeitung
Wächterstraße 76
72074 Tübingen
E-Mail: ramon.pfeiffer at uni-tuebingen.de
Telefon: +49-7071-29-70213
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 5217 bytes
Desc: S/MIME Cryptographic Signature
URL: <http://shibboleth.net/pipermail/users/attachments/20170718/b7dfeea2/attachment.p7s>
More information about the users
mailing list