You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Nick Sullivan edited this page Oct 13, 2015
·
1 revision
The current auth provider in CFSSL uses a static key, and therefore is difficult to rotate in the case of a key compromise. CFSSL should support a token-based authorization system so that authorization credentials can be tied to specific end-entities and time-boxed.