<html><body><div style="font-family: arial, helvetica, sans-serif; font-size: 10pt; color: #000000"><div><style><!--

@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}

p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:12.0pt;
        font-family:"Times New Roman",serif;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:#0563C1;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:#954F72;
        text-decoration:underline;}
p.msonormal0, li.msonormal0, div.msonormal0
        {mso-style-name:msonormal;
        mso-margin-top-alt:auto;
        margin-right:0in;
        mso-margin-bottom-alt:auto;
        margin-left:0in;
        font-size:12.0pt;
        font-family:"Times New Roman",serif;}
span.EmailStyle18
        {mso-style-type:personal-reply;
        font-family:"Calibri",sans-serif;
        color:#1F497D;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-family:"Calibri",sans-serif;}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style></div><div>Hi,</div><div><br data-mce-bogus="1"></div><div>Actually no storage services are used for the state of refresh tokens with the current implementation. They contain all the data by themselves in encrypted form. Their IDs are verified against revocation cache that can be set with the idp.oidc.revocationCache.StorageService -property (shibboleth.StorageService by default).</div><div><br data-mce-bogus="1"></div><div>The lifetime of the refresh tokens can be set in the profile configuration, see <a href="https://github.com/CSCfi/shibboleth-idp-oidc-extension/wiki/OIDC.SSO" data-mce-href="https://github.com/CSCfi/shibboleth-idp-oidc-extension/wiki/OIDC.SSO">https://github.com/CSCfi/shibboleth-idp-oidc-extension/wiki/OIDC.SSO</a></div><div><br data-mce-bogus="1"></div><div>BR,</div><div>Henri.</div><div><br></div><hr id="zwchr" data-marker="__DIVIDER__"><div data-marker="__HEADERS__"><b>From: </b>"Wessel, Keith" <kwessel@illinois.edu><br><b>To: </b>"Shib Users" <users@shibboleth.net><br><b>Sent: </b>Friday, 30 August, 2019 22:37:56<br><b>Subject: </b>RE: OIDC extension: refresh and validate endpoints?<br></div><div><br></div><div data-marker="__QUOTED_TEXT__">






<div class="WordSection1">
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">Thanks, Liam. And would that use the same session storage as my IdP’s session storage for SAML-based sessions? I assume they’re the same.</span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"> </span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">Keith</span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"> </span></p>
<p class="MsoNormal"><a name="_MailEndCompose"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"> </span></a></p>
<span style="mso-bookmark:_MailEndCompose"></span>
<p class="MsoNormal"><b><span style="font-size:11.0pt;font-family:"Calibri",sans-serif">From:</span></b><span style="font-size:11.0pt;font-family:"Calibri",sans-serif"> users <users-bounces@shibboleth.net>
<b>On Behalf Of </b>Liam Hoekenga<br>
<b>Sent:</b> Friday, August 30, 2019 2:28 PM<br>
<b>To:</b> Shib Users <users@shibboleth.net><br>
<b>Subject:</b> Re: OIDC extension: refresh and validate endpoints?</span></p>
<p class="MsoNormal"> </p>
<div>
<div>
<blockquote style="border:none;border-left:solid #CCCCCC 1.0pt;padding:0in 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in">
<p class="MsoNormal">One more question based on what Liam brought up: what property controls the storage service to use for refresh tokens? I don’t see a storage setting for this in idp-oidc.properties. I only see dynamic registrations, remote JWK sets, and
 the revocation cache which, obviously, all must be server-side.</p>
</blockquote>
<div>
<p class="MsoNormal"> </p>
</div>
<div>
<p class="MsoNormal">I'm pretty sure it they just use the same storage service that the rest of the tokens use (session storage)</p>
</div>
<div>
<p class="MsoNormal"> </p>
</div>
<div>
<p class="MsoNormal">Liam </p>
</div>
</div>
</div>
</div>


<br>-- <br>For Consortium Member technical support, see https://wiki.shibboleth.net/confluence/x/coFAAg<br>To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br></div></div></body></html>