[IdPv3] State Management and Clustering

Chad La Joie lajoie at shibboleth.net
Thu Oct 27 15:52:26 BST 2011


Right, that's why we're providing options.  It's abundantly clear when
reviewing those installations that we know about that people won't
setup clustering if it requires *any* additional effort.  So that's
why the default config is to use the cookie.

Those that wish to use the Infnispan clustering option will have a
configuration experience analogous to the configuration of the IdP 1.3
HA-Shib extension.  That is, flip the switch to enable clustering and
then list each node by IP.

On 10/27/11 9:10 AM, Etienne Dysli wrote:
> On 07/10/11 15:06, Chad La Joie wrote:
>> Given these observations, it is our intent to have the *default* 
>> configuration of IdPv3 use cookies (or possibly HTML 5 local
>> storage when available) for that information which is not related
>> to back-channel operations.
> 
> Trusting any state information coming from the client is a
> security issue. Signing the cookie content (as mentioned in
> "[IdPv3] Cookies") could remedy that.
> 
> Still, this state data exchange increases traffic between the
> user's browser and the IdP. Is this worse than increased
> intra-cluster traffic? The answer is different for every deployer I
> guess...
> 
> Regards, Etienne
> 
> 
> 
> 
> -- To unsubscribe from this list send an email to
> dev-unsubscribe at shibboleth.net


More information about the dev mailing list