<div class="gmail_extra"><br><br><div class="gmail_quote">On Tue, Apr 24, 2012 at 4:02 PM, Cantor, Scott <span dir="ltr">&lt;<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>&gt;</span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<div class="im">On 4/24/12 3:40 AM, &quot;Lukas Hämmerle&quot; &lt;<a href="mailto:lukas.haemmerle@switch.ch">lukas.haemmerle@switch.ch</a>&gt; wrote:<br>
&gt;<br>
&gt;All of the above solutions have their limitations and drawbacks.<br>
&gt;Another possible solution could be to extend the SP to remember one IPv4<br>
&gt;and one IPv6 address per client. This may mitigate the issue described<br>
&gt;above. One drawback here could be that this may degrade the security of<br>
&gt;the extended consistentAddress feature as an attacker probably could<br>
&gt;misuse it. So we are wondering what developers think of this?<br>
<br>
</div>But how would the SP know what they were? You mean have it auto-accept the<br>
next address type of the other form it saw?<br></blockquote><div><br></div><div>That&#39;s one way to do it.  The other is if you only have seen only one type of address (say v4) in the session then you get the other type and the cookie otherwise validates, just accept it &amp; store the v6 address.  Next time either of those addresses change then force the re-auth.</div>
<div><br>Dave</div><div><br></div></div><div><br></div>-- <br>David Langenberg<div>Identity Management</div><div>The University of Chicago</div><br>
</div>