rejecting IdP-initiated responses

Cantor, Scott cantor.2 at osu.edu
Sat Apr 14 23:29:37 BST 2012


On 4/14/12 5:52 PM, "Tom Scavo" <trscavo at gmail.com> wrote:
>
>I assume you mean that the SP does not support it. Can this feature be
>added?

You can file it, but I have no plans to work on it imminently, it requires
a large redesign.

> It seems to protect against a stolen or otherwise exposed
>signing key at the IdP.

I don't see how. All an attacker has to do is act as a client, get it to
issue a request, determine the ID to respond to, and then generate a
matching response.

It has other useful security benefits addressing XSRF attacks, but that
doesn't seem like one of them.

-- Scott



More information about the users mailing list