Questions about sealer key rotation

Kelvin Hai kelvin.hai at york.ac.uk
Mon Sep 4 10:13:58 UTC 2023


Hi Scott,

Thanks very much for the clarification.
A couple of more questions:

   - The documentation of the SecretKeyManagement (
   https://shibboleth.atlassian.net/wiki/spaces/IDP4/pages/1265631799/SecretKeyManagement)
   kindly provides two sample scripts to rotate the sealer key and use scp to
   copy the rotated key to other server nodes in a cluster. What happens if
   the sealer files are updated with scp (or similar) whilst shib is running -
   do we need to worry about scp not updating the files atomically?
   - My understanding is that shibboleth stores the shib_idp_session cookie
   as configured with the idp.session.cookieName property in idp.properties.
   The documentation says that the sealer key is used to secure cookies and
   certain other data for the IdPs own use. Could you advise what other data
   for the IdPs is stored in the client storage, please?

Best wishes,
Kelvin
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20230904/47977aea/attachment.htm>


More information about the users mailing list