Revisiting the Defaulting of cookieProps, handlerSSL, etc.
Nate Klingenstein
ndk at internet2.edu
Thu Jun 14 17:27:46 BST 2012
Shib-Dev,
I'm running an Installfest in Saskatoon, and one of the
deployers(responsible for penetration testing in his day job) was
curious as to why we still default to supporting access to handlers
and to content hosted on HTTP. While it's easy enough to enable
secure cookies and SSL-only access, some deployers may be overlooking
that and leaving themselves vulnerable to trivial session hijacking as
a result(particularly with checkAddress and consistentAddress
defaulting to false, though that's for arguably better reasons).
Would it make sense to revisit the distribution config and/or defaults
so that deployers who wanted to support HTTP would have to make the
configuration changes, and not those who would like to ensure secure
access?
Thanks,
Nate.
More information about the dev
mailing list