rejecting IdP-initiated responses
Tom Scavo
trscavo at gmail.com
Sun Apr 15 00:09:06 BST 2012
On Sat, Apr 14, 2012 at 6:29 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:
> On 4/14/12 5:52 PM, "Tom Scavo" <trscavo at gmail.com> wrote:
>>
>> It seems to protect against a stolen or otherwise exposed
>>signing key at the IdP.
>
> I don't see how. All an attacker has to do is act as a client, get it to
> issue a request, determine the ID to respond to, and then generate a
> matching response.
Yeah, I think you're right, in which case I'm not keen on having the feature.
Thanks,
Tom
More information about the users
mailing list