Silhouette has in its seed project in config file two lines I don't understand:
authenticator.cookie.signer.key = "[changeme]" // A unique encryption key
authenticator.crypter.key = "[changeme]" // A unique encryption key
Can somebody tell me what are these used for, if I need them for my https web page and how to generate these keys. There is no info in docs.
This is attempting to crypt the authenticator
cookie generated by Silhouette.
To generate both encryption keys (both different) you could use the playGenerateSecret
task coming from activator
(see https://www.playframework.com/documentation/2.5.x/ApplicationSecret) and copy/paste the generated value.
Your authenticator
cookie is now strongly encrypted :
authenticator=1-9281212ae68b1a47807f25a156d8fc9f1cdfb552-1-oU4BQI8J7OAHzvPQ7E5TEFhZHzmAyDisXabBng9onq3qwwUv1Z+F+xqj0mtVm/SBYUTAQCZWXL+iAh0CQgDX6Ywal1UkE3MXWdBf4KRK3YgA9n9Gnx9mdpHGYd/lHvKkn6tToZkZ4nyYHI8jlsPJP5fbpZpYWKBK4M8tkrHj6/ddXqxHGyhMWHIOBsRZHY84wbrQbqmB3rmjIuiGqIJXUyonnc/UmCt3BcOGD1h+SyFlCbZ8RkjoTjA4s2a3I9vOa4EGMGFRQ3J7OQrx8aIQJrrzvDp9yc2WbCOLYkXhVY/YV1gUAhoUtczWEUbdGaa9efMqhTlhZWKN+adSvkK/XFcUAVvOknrbSEP7CntSLQ5DJMmfICU1FRMf8rh0em1LnsmkgwIG1gEQf3M4toNVL5xEa5ihbTPbusX3E1lQ+BqXvqS7q2h80CTY1D7EVj/oS+cDCOnoYC44l243e5pTPbIhIGtFICVjc3MY0qLmPoyY33zZzmRXx4aue0gKyCrReOJ3o9Lvw13xHv67hwbPM5p9AJlDHmyvWjkPZmv2Szp1DFxSZfNefS3xWHw13cq10YISSt7RKhc2SAJTVMgPb3c57xD/Rru9YhuCoCs8ADipHoDeAgJkwjNabkpk2RcvLLV+WvRja310qvKeXC2Cl9zmqJXgqEeNJgqWLQ==
If you love us? You can donate to us via Paypal or buy me a coffee so we can maintain and grow! Thank you!
Donate Us With