oneconcern / keycloak-gatekeeper

A OpenID / Keycloak Proxy service
Apache License 2.0
62 stars 6 forks source link

Improve cookie encryption #11

Open fredbi opened 5 years ago

fredbi commented 5 years ago

Cookie encryption currently only supports AES-256 with GCM cipher this is better: https://eprint.iacr.org/2017/697.pdf

Alternatively (or in addition), we might favor cookie secret key rotation...

fredbi commented 5 years ago

This would be a personal research project, following https://datatracker.ietf.org/meeting/100/materials/slides-100-cfrg-re-keying-mechanisms-for-symmetric-keys/