Question on IDP session randomness (low entrophy)
Anand Somani
meatforums at gmail.com
Tue Dec 11 12:49:10 EST 2012
Hi,
We are using shibboleth-idp (2.3.5) on jetty (7.5.4) with JAAS. Now our
intention is to keep the IDP stateless, but I think there is some session
data sharing between the login and assertion generation modules and so
requires the session to still be valid for a small duration (abt a second).
Our security team did test around our setup and said that the session was
randomness was unacceptable (low entrophy) and was susceptible to
prediction attacks, so I wonder if there is something I am doing wrong, so
- Am I configuring something incorrectly?
- Is is a jetty thing or something in Shibboleth?
- Is this a known issue, is there a JIRA around this?
Thanks
Anand
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20121211/30a8a128/attachment.html
More information about the users
mailing list