How long should the SAML token be installed

Is there any advice on how long the SAML token should be installed (in the SOA infrastructure)? I thought about a few (6-12) hours.

thank you very much Marcus

+3
source share
1 answer

It’s usually a bad idea to have such a long life for your tokens, because they can theoretically be “stolen” and reused. Issuing a token should not be particularly timely, so I would recommend that you re-check your users with STS quite often, and let your token “live” for several minutes.

+5
source

Source: https://habr.com/ru/post/1730851/


All Articles