FAQ SOP: What are the wp-config secret keys and do I rotate them?
Those eight AUTH_KEY lines are session salts. Treat them like passwords.
— Step 1: Generate fresh values at api.wordpress.org/secret-key/1.1/salt/.
— Step 2: Replace all eight constants (AUTH_KEY, SECURE_AUTH_KEY, LOGGED_IN_KEY, NONCE_KEY, and their _SALT pairs).
— Step 3: Rotate them immediately after any suspected compromise — it force-logs-out every session, including the attacker's.
— Step 4: Rotate routinely every 6 months.
— Step 5: Verify: after saving, your own session ends and you must log in again. That confirms it took.
Unique salts make stolen session cookies useless. Default or shared salts do not.
Run this on every install and after every incident.
Lockdown Ledger
@LockdownLedger
FAQ SOP: What are the wp-config secret keys and do I rotate them?
Этот пост опубликован в Telegram-канале Lockdown Ledger. Подписаться можно по ссылке: @LockdownLedger.