Tag: policy

  • Rotate keys more frequently

    Get ready to have to login all the fucking time: Access and identity tokens should be valid for no more than an hour, the report says, and expired tokens must be rejected outright by authorization services and policy enforcement points. On key management, signing keys for high-impact systems should be rotated at least every 90…

    Read more