Any changes in OIDC RP overrides between V1 and V2?

Wessel, Keith kwessel at illinois.edu
Wed Mar 31 18:51:05 UTC 2021


Thanks, Scott. Now if we can just figure out how to get AWS SecretsManager to retain more than the current and previous values of a secret, we'll have this fixed.

Looks like the refresh token lifetime of P1Y wasn't the problem at all and, as Jim said, that's valid.

Keith


-----Original Message-----
From: users <users-bounces at shibboleth.net> On Behalf Of Cantor, Scott
Sent: Tuesday, March 30, 2021 7:31 AM
To: Shib Users <users at shibboleth.net>
Subject: Re: Any changes in OIDC RP overrides between V1 and V2?

On 3/29/21, 9:26 PM, "users on behalf of Wessel, Keith" <users-bounces at shibboleth.net on behalf of kwessel at illinois.edu> wrote:

>    One more theory with this issue that I wanted to run past those who know the code better than me. If the
> data sealer key that was the current secret when the refresh token was generated is no longer available to the
> IdP, will the IdP refuse the refresh token?

Yes.

-- Scott


-- 
For Consortium Member technical support, see https://urldefense.com/v3/__https://wiki.shibboleth.net/confluence/x/coFAAg__;!!DZ3fjg!sCLgvhRzfI7GXgxcUdigw16MQY03TY9_qq6AifYMADLtPJmLXFpj1jXObw7QmKAqvA$ 
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net


More information about the users mailing list