On Jan 10, 2014, at 9:14 AM, Toby Elliott <telli...@mozilla.com> wrote:

> On possibility that Ryan and I discussed - if the tokenserver gets a new 
> generation cert, it immediately rejects and backs off all clients of that 
> account for the token expiry period. That way we can guarantee that when the 
> writes start again, every client is using the new key.
> 

Can you say a little more about what this means? What does "rejects and backs 
off all clients of that account for the token expiry period" imply? Does this 
mean other clients can't re-login to Sync for time period equal to the lifetime 
of a token?

-chris



> It's a little hacky, but it buys us time to develop the proper solution 
> (which probably involves better use of X-if-unmodified-since).
> 
> Toby
> 
> 
> 

_______________________________________________
Sync-dev mailing list
Sync-dev@mozilla.org
https://mail.mozilla.org/listinfo/sync-dev

Reply via email to