Developer

 View Only
last person joined: 2 days ago 

Expand all | Collapse all

Rotate or Change Client Secret?

This thread has been viewed 12 times
  • 1.  Rotate or Change Client Secret?

    Posted Aug 17, 2022 02:49 PM

    Does anyone know of a way to programmatically change the Client Secret?

    We need to rotate the client secret every so often due to security policy and I can't find a way other than manually deleting the listing under My Apps & Tokens.

    Thank you!



  • 2.  RE: Rotate or Change Client Secret?

    EMPLOYEE
    Posted Aug 18, 2022 07:59 AM
    Check this video on how authentication, token-refresh/rotation works.

    Client secret is only needed first time when you request an access token. Also, the client secret is only useful when combined with a user authentication which I think is easier to change. I have not seen an API to change the client secret, but because just a client secret is not providing access, the security policy may need to be re-evaluated.

    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------