<div dir="ltr">hello,<br><br>I am working on setting up a credential store of sorts for OIDC Client Secrets. We are using the ResolverServiceClientSecretValueResolver to resolve these secrets from an LDAP DataSource, and it is working as expected.<br><br>One question I have is in regards to the comment on the following page regarding Hashed Secrets:<br><a href="https://shibboleth.atlassian.net/wiki/spaces/IDPPLUGINS/pages/1376879133/OPMetadataClientRegistration#Hashed-Secrets-3.1">https://shibboleth.atlassian.net/wiki/spaces/IDPPLUGINS/pages/1376879133/OPMetadataClientRegistration#Hashed-Secrets-3.1</a><br><br>Is this saying that I can take the OIDC Client Secret generated by the OIDC registration process, run it through a SHA-256 Hash, Base64 the results, and append '{SHA2}' to the resulting string, and stick THAT in my LDAP attribute, or is it saying something else?<br><br>I'm trying to avoid putting the client secret in cleartext in LDAP, and this appears to be an answer to that, but I wanted to be sure I was understanding that properly.<div><br></div><div>thanks for any help!<br><div><br><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><font color="#888888">**</font><br style="color:rgb(136,136,136)"><div dir="ltr" style="color:rgb(136,136,136)"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr">Nathan Lewan<div>University of Maryland<br></div></div></div></div></div></div></div></div></div></div></div></div>