DEFAULT SPLICE CONFIGURATION CHANGE IMPACTING USERS OF EXTERNAL KMS SYSTEMS
validator-announce1 messagesstarted 02-03-2026
- Splice 0.5.14 will increase the default lifetime of cached session encryption keys from 10 minutes to 1 hour, improving performance and reducing KMS costs.For participants not using an external KMS, there is no practical security impact. For KMS-enabled participants, this extends the window of messages that an adversary with access to a memory snapshot could decrypt. The parameters are configurable if you'd like to tune them.Details: https://github.com/hyperledger-labs/splice/pull/4168(details will also be included in the Splice 0.5.14 docs, once 0.5.14 is released)