consistentAddress, IPv6 and Happy Eyeballs
David Langenberg
davel at uchicago.edu
Tue Apr 24 23:29:45 BST 2012
On Tue, Apr 24, 2012 at 4:02 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:
> On 4/24/12 3:40 AM, "Lukas Hämmerle" <lukas.haemmerle at switch.ch> wrote:
> >
> >All of the above solutions have their limitations and drawbacks.
> >Another possible solution could be to extend the SP to remember one IPv4
> >and one IPv6 address per client. This may mitigate the issue described
> >above. One drawback here could be that this may degrade the security of
> >the extended consistentAddress feature as an attacker probably could
> >misuse it. So we are wondering what developers think of this?
>
> But how would the SP know what they were? You mean have it auto-accept the
> next address type of the other form it saw?
>
That's one way to do it. The other is if you only have seen only one type
of address (say v4) in the session then you get the other type and the
cookie otherwise validates, just accept it & store the v6 address. Next
time either of those addresses change then force the re-auth.
Dave
--
David Langenberg
Identity Management
The University of Chicago
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/dev/attachments/20120424/0189f303/attachment.html
More information about the dev
mailing list