<div dir="ltr">Dear Knowledgeable People,<br><br>Could anyone share their experience of sealer keys rotation (as documented in <a href="https://shibboleth.atlassian.net/wiki/spaces/IDP4/pages/1265631799/SecretKeyManagement">https://shibboleth.atlassian.net/wiki/spaces/IDP4/pages/1265631799/SecretKeyManagement</a>)?<br>How often do you rotate the key and how many old keys do you keep?<div>  <br>We are trying to find out the implication when an old key is no longer accessible. If we rotate the key daily and keep 30 old keys, what happens if someone has given consent to an SP but doesn't log in to that SP in a 30 day period? Furthermore, if they log in to any shibboleth-protected SP, is that sufficient to ensure the consent for all SPs is not lost?<br><br>Also when the sealer is rotated - does shibboleth automatically pick up the new key or we'll need to restart the shibboleth service?</div><div><br>Best wishes,<br>Kelvin<br><span class="gmail_signature_prefix">-- </span><br><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div style="font-size:small"><font face="monospace, monospace">Kelvin Hai<br></font></div><div style="font-size:small"><font face="monospace, monospace">Identity Systems Developer</font></div><div style="font-size:small"><font face="monospace, monospace">IT Services, University of York, Heslington, York, North Yorkshire, YO10 5DD, United Kingdom</font></div><div style="font-size:small"><br></div></div></div></div></div></div></div></div></div></div></div></div></div>