Enforce expiration for client secret for confidential applications
Organization Name (Required - If you are an Oracle Partner, please provide the organization you are logging the idea on behalf of):
Berkshire Hathaway Energy (BHE)
Description (Required):
Client secrets for confidential applications do not expire. They should have a defined expiration date. Once a client secret expires it should no longer be usable.
Use Case and Business Need (Required):
Confidential application client ID and secrets are used to secure access to sensitive data via OAuth. Security guidelines require these credentials to expire and need to be regenerated on a regular basis.
Enhancement Request / Service Request: