开发者

How long should a SAML Token be valid

开发者 https://www.devze.com 2022-12-18 22:46 出处:网络
has anybody an advice, how long a SAML Token should be valid (in a SOA inf开发者_运维技巧rastructure)?

has anybody an advice, how long a SAML Token should be valid (in a SOA inf开发者_运维技巧rastructure)? I thought of several (6-12) hours.

many thanks Markus


It is generally a bad idea to have such a high lifetime for your tokens, because they can theoretically be "stolen" and reused. Token issuance should not be an especially timely affair, so I would recommend that you reauthenticate your users with the STS quite often, and only let your token "live" for a few minutes.

0

精彩评论

暂无评论...
验证码 换一张
取 消

关注公众号