Question on IDP session randomness (low entrophy)

Anand Somani meatforums at gmail.com
Tue Dec 11 12:49:10 EST 2012


Hi,

We are using shibboleth-idp (2.3.5) on jetty (7.5.4) with JAAS. Now our
intention is to keep the IDP stateless, but I think there is some session
data sharing between the login and assertion generation modules and so
requires the session to still be valid for a small duration (abt a second).

Our security team did test around our setup and said that the session was
randomness was unacceptable (low entrophy) and was susceptible to
prediction attacks, so I wonder if there is something I am doing wrong, so

   - Am I configuring something incorrectly?
   - Is is a jetty thing or something in Shibboleth?
   - Is this a known issue, is there a JIRA around this?

Thanks
Anand
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20121211/30a8a128/attachment.html 


More information about the users mailing list