<div dir="ltr"><div>Hi Scott,</div><div><br></div>Thanks very much for the clarification.<div>A couple of more questions:</div><div><ul><li>The documentation of the SecretKeyManagement (<a href="https://shibboleth.atlassian.net/wiki/spaces/IDP4/pages/1265631799/SecretKeyManagement">https://shibboleth.atlassian.net/wiki/spaces/IDP4/pages/1265631799/SecretKeyManagement</a>) kindly provides two sample scripts to rotate the sealer key and use scp to copy the rotated key to other server nodes in a cluster. What happens if the sealer files are updated with scp (or similar) whilst shib is running - do we need to worry about scp not updating the files atomically?</li><li>My understanding is that shibboleth stores the shib_idp_session cookie as configured with the idp.session.cookieName property in idp.properties. The documentation says that the sealer key is used to secure cookies and certain other data for the IdPs own use. Could you advise what other data for the IdPs is stored in the client storage, please? <br></li></ul>Best wishes,</div><div>Kelvin</div><div dir="ltr" class="gmail_signature"><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"></div></div></div></div></div></div></div></div></div></div></div></div></div>