Datasealer key rotation and CAS

Cantor, Scott cantor.2 at osu.edu
Tue Oct 27 12:26:54 UTC 2020


On 10/27/20, 3:19 AM, "users on behalf of Paul B. Henson" <users-bounces at shibboleth.net on behalf of henson at cpp.edu> wrote:

>    Is this something that would be relatively easy to implement, or very difficult within the existing framework?

I don't know if it's possible, but it should be totally unneeded. If it gets a piece of data encrypted with a non-default key it should simply fetch the key. That should be true whether it's a newer or older one.

-- Scott




More information about the users mailing list