Revisiting the Defaulting of cookieProps, handlerSSL, etc.

Nate Klingenstein ndk at internet2.edu
Thu Jun 14 17:27:46 BST 2012


Shib-Dev,

I'm running an Installfest in Saskatoon, and one of the  
deployers(responsible for penetration testing in his day job) was  
curious as to why we still default to supporting access to handlers  
and to content hosted on HTTP.  While it's easy enough to enable  
secure cookies and SSL-only access, some deployers may be overlooking  
that and leaving themselves vulnerable to trivial session hijacking as  
a result(particularly with checkAddress and consistentAddress  
defaulting to false, though that's for arguably better reasons).

Would it make sense to revisit the distribution config and/or defaults  
so that deployers who wanted to support HTTP would have to make the  
configuration changes, and not those who would like to ensure secure  
access?

Thanks,
Nate.


More information about the dev mailing list