Skip to content

Switch AAL2 remembered device expiration configuration units from hours to minutes#9000

Merged
mitchellhenke merged 1 commit intomainfrom
mitchellhenke/switch-aal-2-remembered-device-to-minutes
Aug 14, 2023
Merged

Switch AAL2 remembered device expiration configuration units from hours to minutes#9000
mitchellhenke merged 1 commit intomainfrom
mitchellhenke/switch-aal-2-remembered-device-to-minutes

Conversation

@mitchellhenke
Copy link
Contributor

🛠 Summary of changes

In #8926, we switched the default to 0 hours, which is now consistent in all live environments. However, using hours as the unit of time is limiting. NIST 800-63B specifies one of the AAL2 re-authentication limits as 30 minutes, which we would not be able to do at the moment. We do not have any timeline for changing the value from zero, but this PR switches the unit of time to minutes to give us flexibility moving forward.

…rs to minutes

changelog: Internal, Configuration, Switch AAL2 remembered device expiration configuration units from hours to minutes
@mitchellhenke mitchellhenke merged commit ff66024 into main Aug 14, 2023
@mitchellhenke mitchellhenke deleted the mitchellhenke/switch-aal-2-remembered-device-to-minutes branch August 14, 2023 19:32
@jmdembe jmdembe mentioned this pull request Aug 15, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants