sanity check : idp front end

Tom Zeller tzeller at dragonacea.biz
Wed Oct 2 10:52:16 EDT 2013


Looking for a sanity check on the idea of running a front end to the
IdP primarily for the purpose of binding a privileged port as root, as
an option when setuid is not desirable.

I think such a front end would be a transparent reverse tunneling
proxy, but I really do not understand what happens to SSL/TLS on
either side of the mitm, and I do not understand the implications.

Some notes : https://wiki.shibboleth.net/confluence/x/qQHN


More information about the dev mailing list