Questions about sealer key rotation
Kelvin Hai
kelvin.hai at york.ac.uk
Fri Sep 1 14:40:48 UTC 2023
Dear Knowledgeable People,
Could anyone share their experience of sealer keys rotation (as documented
in
https://shibboleth.atlassian.net/wiki/spaces/IDP4/pages/1265631799/SecretKeyManagement
)?
How often do you rotate the key and how many old keys do you keep?
We are trying to find out the implication when an old key is no longer
accessible. If we rotate the key daily and keep 30 old keys, what happens
if someone has given consent to an SP but doesn't log in to that SP in a 30
day period? Furthermore, if they log in to any shibboleth-protected SP, is
that sufficient to ensure the consent for all SPs is not lost?
Also when the sealer is rotated - does shibboleth automatically pick up the
new key or we'll need to restart the shibboleth service?
Best wishes,
Kelvin
--
Kelvin Hai
Identity Systems Developer
IT Services, University of York, Heslington, York, North Yorkshire, YO10
5DD, United Kingdom
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20230901/a15ad1d5/attachment.htm>
More information about the users
mailing list