Previous Topic: Manually Rollover the KeyNext Topic: Generate a Session Ticket Key


Change Static Keys

You can change the static Agent key used by SiteMinder Web Agents to encrypt identity information for certain SiteMinder features.

Important! Changing the static key is not recommended because the change can cause some SiteMinder features to lose the data they require to function properly. Features that establish and use an identity stored in a persistent cookie will no longer work. Change the static key only in extreme situations such as security breaches. Authenticated users may be forced to login again before single sign-on will function across multiple SiteMinder installations.

A static key may also be used to maintain a single sign-on environment in an environment that requires multiple Policy Servers and multiple master key stores.

To change the static key

  1. Log into the Administrative UI.
  2. From the Administration tab select Policy Server, Key Management.

    The Key Management pane opens.

  3. In the Agent Key group box, select Use Static Key.

    The pane changes to support static keys.

  4. Do one of the following:
  5. Click Rollover Now.

    Depending on the option you selected, the Policy Server generates a new static key or uses the one you specified. The static key rolls over within three minutes.

  6. Click Submit to save your changes.

Manage the Session Ticket Key

The Policy Server can generate the session ticket key using an algorithm, or you can enter the session ticket key manually. A session ticket is established each time a user authenticates successfully and enables the Policy Server to determine how long a user’s session can continue.

Note: The only implementation that requires a manually assigned session ticket key is one that includes multiple, independent key stores. Automatically generated keys cannot be propagated across independent key stores by the Policy Server. In all other instances it is recommended that you use the session ticket key generated by the Policy Server algorithm.