Generate Profile Token Extended (QsyGenPrfTknE) API: Token Expiration

"Holmer, John" <JHolmer-Iv5KO+h6AVCH/[email protected]> Thu, 15 Apr 2010 16:38:17 -0400
Newsgroups gmane.comp.systems.as400.security
Message-ID <2CEA9B835E89634AB7FEB5E4251ABF1C189DB5CA@nahqexs21.na.generalcable.com>
We have created a series of web services that allow access to some
aspects of our system; these services run in the HTTP server on the i.
We have required services that modify any data to require a parameter
that is a token generated from a call to the QsyGenPrfTknE API, this API
call occurred while the user was logging into the larger web app that
consumes the iSeries web services.

 

My question is in regards to the expiration of the token, we pass in the
value 3600 for the parameter Time_out_interval during token creation,
but I would like to know if it always expires in an hour (for my
parameter value of 3600), or if it expires after an hour of inactivity.
If it does expire in an hour, regardless of usage, anyone know of a way
to extend the token?  I would prefer to not generate a new token from
the token passed into the service, because it will be a little bit
painful for us to get that new token back into the calling web
application to be passed back again.
 
Thanks for any input...
 
John

 

_______________________________________________
This is the Security Administration on the AS400 / iSeries (Security400) mailing list
To post a message email: Security400-Zwy7GipZuJhWk0Htik3J/[email protected]
To subscribe, unsubscribe, or change list options,
visit: http://lists.midrange.com/mailman/listinfo/security400
or email: Security400-request-Zwy7GipZuJhWk0Htik3J/[email protected]
Before posting, please take a moment to review the archives
at http://archive.midrange.com/security400.