Previous Topic: Configure Manual Shared Secret Rollover

Next Topic: Configuring Policy Server Logging

Configure Periodic Shared Secret Rollover

The Policy Server supports periodic shared secret rollovers for trusted hosts hourly, daily, weekly, or monthly. The shortest allowable period between rollovers is one hour.

Unlike Agent key rollover, periodic shared secret rollover is associated with the age of the shared secret for each individual trusted host. The Policy Server initiates rollovers based on the age of the shared secret, rather than at a specific time of the day, week, or month. By rolling over each shared secret as it expires, the processing associated with the rollover is distributed over time, and avoids placing a heavy processing load on the Policy Server. However, if you use the manual rollover feature, future periodic rollovers will generally be clustered together for all trusted hosts, since the manual rollover sets new shared secrets for all trusted hosts that allow shared secret rollover.

Important! If you enable key generation on more than one Policy Server associated with a single policy store, the same shared secret can be rolled over more than once in a short period of time due to object store propagation delays. This can result in orphaned hosts whose new shared secrets have been discarded. To avoid this potential problem, enable shared secret rollover for a single Policy Server per policy store.

Note: In order to enable periodic shared secret rollover, the Enable Agent Key Generation check box must be selected in the Keys tab of the Policy Server Management Console.

To configure periodic shared secret rollover

  1. Log into the Policy Server User Interface.
  2. From the menu bar of the SiteMinder Administration window, select Tools, Manage Keys.

    The SiteMinder Key Management dialog box opens.

  3. Select the Shared Secret Rollover tab.
  4. In the Shared Secret Rollover tab, select the Rollover Shared Secret every radio button.
  5. Enter a number in the first field to the right of the radio button and select a unit (Hours, Days, Weeks, or Months) from the drop-down list.
  6. Click OK.

More information:

Configure Periodic Key Rollover

Management Console--Keys Tab