开发者

How long should a SAML Token be valid

has anybody an advice, how long a SAML Token should be valid (in a SOA inf开发者_运维技巧rastructure)? I thought of several (6-12) hours.

many thanks Markus


It is generally a bad idea to have such a high lifetime for your tokens, because they can theoretically be "stolen" and reused. Token issuance should not be an especially timely affair, so I would recommend that you reauthenticate your users with the STS quite often, and only let your token "live" for a few minutes.

0

上一篇:

下一篇:

精彩评论

暂无评论...
验证码 换一张
取 消

最新问答

问答排行榜