How long are the ticker in UMA valid?

Tagged: ,

This topic has 0 replies, 1 voice, and was last updated 5 years, 1 month ago by tomoko.

  • Author
  • #17922

    Checking UMA flow for accessing an uma protected resource, i see it is necesary for the Resource Server to create a ticket. And to do so, it is necesary the PAT, that is created when the resource owner is “logged into” the system.
    I would like to create a system that allows to access to resource without intervention of the res owner after he allows access to it (create policy).

    To do so, I have got two ideas:
    -store the PAT created when creating the resource, for later use. And refresh it continously internally in my component (using refresh endpoint). Each time a requesting party tries to access, recreate all the ticket, AAT, and RPT

    -create a ticket when creating the policy allowing acces to requesting party, and send the ticket to requesting party for accesing it. so the req party uses the ticket each time he wants to access the ticket

    But i got a doubt: what is the life time of a ticket in UMA? Can be used several times?

Viewing 1 post (of 1 total)

You must be logged in to reply to this topic.

©2022 ForgeRock - we provide an identity and access platform to secure every online relationship for the enterprise market, educational sector and even entire countries. Click to view our privacy policy and terms of use.

Log in with your credentials

Forgot your details?