Datasealer key rotation and CAS
Cantor, Scott
cantor.2 at osu.edu
Tue Oct 27 12:38:00 UTC 2020
On 10/27/20, 8:27 AM, "users on behalf of Cantor, Scott" <users-bounces at shibboleth.net on behalf of cantor.2 at osu.edu> wrote:
> I don't know if it's possible, but it should be totally unneeded. If it gets a piece of data encrypted with a non-default key
> it should simply fetch the key. That should be true whether it's a newer or older one.
In fact, to be clear, the code doesn't deal in "new" or "old". The fact I use numbers by default was just an obvious convenience to make it easy to produce unique labels. All the code knows is "default" or "not default, must read from keystore".
-- Scott
More information about the users
mailing list