Cookie Encryption Key

Ramon Pfeiffer ramon.pfeiffer at uni-tuebingen.de
Thu Jul 20 05:34:48 EDT 2017


On 19.07.2017 15:54, Cantor, Scott wrote:
> On 7/19/17, 2:37 AM, "users on behalf of Ramon Pfeiffer" <users-bounces at shibboleth.net on behalf of ramon.pfeiffer at uni-tuebingen.de> wrote:
> 
>> Am I correct that the sessions of a user are then stored in the backing
>> storage so that it will survive a failover between my two nodes?
> 
> If it's not mid-request, yes.
> 
>> What do you mean by "that's generally a non-issue now"?
> 
> I meant needing queries is generally not common now. The main purpose of the key is sessions, not queries.
> 

To recap then:
- My sessions are stored in a backing storage and can survive a failover and
- I don't mind if I cannot use attribute queries with transient IDs.

If I understand the wiki page and its implications correctly, I can now
safely disable the use of the Cookie Encryption Key?

Thanks again for clarifying
Ramon

--
Universität Tübingen
Zentrum für Datenverarbeitung
Wächterstraße 76
72074 Tübingen

E-Mail: ramon.pfeiffer at uni-tuebingen.de
Telefon: +49-7071-29-70213

-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 5217 bytes
Desc: S/MIME Cryptographic Signature
URL: <http://shibboleth.net/pipermail/users/attachments/20170720/a38c2af5/attachment-0001.p7s>


More information about the users mailing list