Questions about sealer key rotation
Kelvin Hai
kelvin.hai at york.ac.uk
Mon Sep 4 10:13:58 UTC 2023
Hi Scott,
Thanks very much for the clarification.
A couple of more questions:
- The documentation of the SecretKeyManagement (
https://shibboleth.atlassian.net/wiki/spaces/IDP4/pages/1265631799/SecretKeyManagement)
kindly provides two sample scripts to rotate the sealer key and use scp to
copy the rotated key to other server nodes in a cluster. What happens if
the sealer files are updated with scp (or similar) whilst shib is running -
do we need to worry about scp not updating the files atomically?
- My understanding is that shibboleth stores the shib_idp_session cookie
as configured with the idp.session.cookieName property in idp.properties.
The documentation says that the sealer key is used to secure cookies and
certain other data for the IdPs own use. Could you advise what other data
for the IdPs is stored in the client storage, please?
Best wishes,
Kelvin
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20230904/47977aea/attachment.htm>
More information about the users
mailing list