<div dir="ltr"><div>Hello!</div><div><br></div><div>We're using Shibboleth IdP 3.2.0 and noticed what looks like a temporary encryption of user credentials in the session persistence backend. They seem to be reversibly encrypted using a time-bound id-aes128-gcm cipher, random initialization vector + current master key from JKS storage.<br></div><div><br></div><div>I would like to understand the need for this and if there is a way to turn if off somewhere in the configuration. They do seem to be purged automatically after some time but still, why is there a need to store them? </div><div><br></div><div>Thanks!</div></div>