[IdPv3] State Management and Clustering
Chad La Joie
lajoie at shibboleth.net
Thu Oct 27 15:52:26 BST 2011
Right, that's why we're providing options. It's abundantly clear when
reviewing those installations that we know about that people won't
setup clustering if it requires *any* additional effort. So that's
why the default config is to use the cookie.
Those that wish to use the Infnispan clustering option will have a
configuration experience analogous to the configuration of the IdP 1.3
HA-Shib extension. That is, flip the switch to enable clustering and
then list each node by IP.
On 10/27/11 9:10 AM, Etienne Dysli wrote:
> On 07/10/11 15:06, Chad La Joie wrote:
>> Given these observations, it is our intent to have the *default*
>> configuration of IdPv3 use cookies (or possibly HTML 5 local
>> storage when available) for that information which is not related
>> to back-channel operations.
>
> Trusting any state information coming from the client is a
> security issue. Signing the cookie content (as mentioned in
> "[IdPv3] Cookies") could remedy that.
>
> Still, this state data exchange increases traffic between the
> user's browser and the IdP. Is this worse than increased
> intra-cluster traffic? The answer is different for every deployer I
> guess...
>
> Regards, Etienne
>
>
>
>
> -- To unsubscribe from this list send an email to
> dev-unsubscribe at shibboleth.net
More information about the dev
mailing list