Encrypting OIDC secrets in static metadata

Wessel, Keith kwessel at illinois.edu
Mon Sep 30 22:04:10 UTC 2024


Hi, All,

Just making sure I'm not missing anything before I make a feature request about this.

I see that OIDC client secrets in the IdP can now be SHA hashed which, as the documentation says, doesn't encrypt them but at least slightly obfuscates them.

Is it possible, or are there plans to make it possible, to encrypt those stored secrets with some key known only to the IdP? Seems trivial enough with a two-way encryption algorithm used from my novice perspective.

We'd like to start storing some metadata and other configs in a Github repo for version control. It'll be private, but we still would prefer things to be encrypted if they're secrets. If two-way encryption can't happen, any other thoughts on how we might accomplish this?

Thanks,
Keith

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20240930/ac000d29/attachment.htm>


More information about the users mailing list