SP issue: Shib-Identity-Provider not set for some IdPs
Sara Hopkins
sara.hopkins at ed.ac.uk
Mon Apr 2 17:09:19 BST 2012
Many thanks Scott and Peter for your replies. I'll push them to upgrade
as you say.
Cheers,
Sara
On 31/03/2012 18:21, Cantor, Scott wrote:
> On 3/31/12 8:09 AM, "Peter Schober"<peter.schober at univie.ac.at> wrote:
>
>> * Sara Hopkins<sara.hopkins at ed.ac.uk> [2012-03-31 01:22]:
>>> I'm trying to help a client just now whose SP (Shibboleth 2.0 or 2.1 I
>>> believe) is seeing that the Shib-Identity-Provider variable is set upon
>>> authentication for some IdPs but not for others.
>>
>> Until or in 2.1 there was a bug where Shib-Identity-Provider
>> sometimes was not set. I can't recall the specifics but either way
>> they shouldn't be running 2.1 anyway.
>
> Yes, I believe it related to encryption and signing in a particular
> combination. The security wasn't compromised, but the information being
> pulled from the response wasn't handled properly.
>
> Technically it's possible when creating a session to not have an issuer,
> that's why the code doesn't crash. But it's not consistent with any
> security model supported by the built-in code, so that's an unintentional
> situation right now.
>
> -- Scott
>
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
>
--
Sara Hopkins
Support Team
UK Access Management Federation for Education and Research
web: http://www.ukfederation.org.uk/
The University of Edinburgh is a charitable body, registered in
Scotland, with registration number SC005336.
More information about the users
mailing list