SP issue: Shib-Identity-Provider not set for some IdPs

Sara Hopkins sara.hopkins at ed.ac.uk
Mon Apr 2 17:09:19 BST 2012


Many thanks Scott and Peter for your replies. I'll push them to upgrade 
as you say.

Cheers,

Sara

On 31/03/2012 18:21, Cantor, Scott wrote:
> On 3/31/12 8:09 AM, "Peter Schober"<peter.schober at univie.ac.at>  wrote:
>
>> * Sara Hopkins<sara.hopkins at ed.ac.uk>  [2012-03-31 01:22]:
>>> I'm trying to help a client just now whose SP (Shibboleth 2.0 or 2.1 I
>>> believe) is seeing that the Shib-Identity-Provider variable is set upon
>>> authentication for some IdPs but not for others.
>>
>> Until or in 2.1 there was a bug where Shib-Identity-Provider
>> sometimes was not set. I can't recall the specifics but either way
>> they shouldn't be running 2.1 anyway.
>
> Yes, I believe it related to encryption and signing in a particular
> combination. The security wasn't compromised, but the information being
> pulled from the response wasn't handled properly.
>
> Technically it's possible when creating a session to not have an issuer,
> that's why the code doesn't crash. But it's not consistent with any
> security model supported by the built-in code, so that's an unintentional
> situation right now.
>
> -- Scott
>
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
>

-- 
Sara Hopkins
Support Team
UK Access Management Federation for Education and Research
web:    http://www.ukfederation.org.uk/

The University of Edinburgh is a charitable body, registered in
Scotland, with registration number SC005336.


More information about the users mailing list