Any changes in OIDC RP overrides between V1 and V2?
Wessel, Keith
kwessel at illinois.edu
Wed Mar 31 18:51:05 UTC 2021
Thanks, Scott. Now if we can just figure out how to get AWS SecretsManager to retain more than the current and previous values of a secret, we'll have this fixed.
Looks like the refresh token lifetime of P1Y wasn't the problem at all and, as Jim said, that's valid.
Keith
-----Original Message-----
From: users <users-bounces at shibboleth.net> On Behalf Of Cantor, Scott
Sent: Tuesday, March 30, 2021 7:31 AM
To: Shib Users <users at shibboleth.net>
Subject: Re: Any changes in OIDC RP overrides between V1 and V2?
On 3/29/21, 9:26 PM, "users on behalf of Wessel, Keith" <users-bounces at shibboleth.net on behalf of kwessel at illinois.edu> wrote:
> One more theory with this issue that I wanted to run past those who know the code better than me. If the
> data sealer key that was the current secret when the refresh token was generated is no longer available to the
> IdP, will the IdP refuse the refresh token?
Yes.
-- Scott
--
For Consortium Member technical support, see https://urldefense.com/v3/__https://wiki.shibboleth.net/confluence/x/coFAAg__;!!DZ3fjg!sCLgvhRzfI7GXgxcUdigw16MQY03TY9_qq6AifYMADLtPJmLXFpj1jXObw7QmKAqvA$
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
More information about the users
mailing list