Any changes in OIDC RP overrides between V1 and V2?

Wessel, Keith kwessel at illinois.edu
Wed Mar 31 19:05:24 UTC 2021


I had considered that, or more specifically, putting them on an S3 volume. We could spin up a scheduled task on a regular basis that runs the update script to rotate the keys. We're already mounting files from EFS (local metadata and attribute filters), so there's not much else to add to the containers.

The use of SecretsManager and a Lambda function is extremely cool, but utterly useless if we can only keep the current and previous data sealer keys around. I've asked AWS for help, but your and my thinking is my solid plan B.

Keith


-----Original Message-----
From: users <users-bounces at shibboleth.net> On Behalf Of Cantor, Scott
Sent: Wednesday, March 31, 2021 1:54 PM
To: Shib Users <users at shibboleth.net>
Subject: Re: Any changes in OIDC RP overrides between V1 and V2?

On 3/31/21, 2:51 PM, "users on behalf of Wessel, Keith" <users-bounces at shibboleth.net on behalf of kwessel at illinois.edu> wrote:

>    Thanks, Scott. Now if we can just figure out how to get AWS 
> SecretsManager to retain more than the current and previous values of a secret, we'll have this fixed.

Maybe just stick the usual keyfiles into S3 and share it to the hosts that way?

-- Scott


--
For Consortium Member technical support, see https://urldefense.com/v3/__https://wiki.shibboleth.net/confluence/x/coFAAg__;!!DZ3fjg!tAZdo7gCfKWKqGncoRXSNf3QwxwWKal1efwmSiPJcJs7L-IwhN9vVrfECs9m9Ozq7w$
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net


More information about the users mailing list