IdP cookie protection

Aleksandar Likic aleksandar.likic at securekey.com
Thu Feb 23 14:13:03 GMT 2012


Hello,

We are investigating possible security risks with using shibboleth. In particular, the risk of stealing IdP cookies and thus gaining access to another user's IdP session. I see in the docs that shibooleth IdP has some protection against this kind of attack, like consistentAddress property. Is there somewhere a complete list of features provided by shibboleth in this regard? What would be the best practices that one should employ during shibboleth deployment to protect from this?

Thanks,
Aleks
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20120223/fbe4c012/attachment-0001.html 


More information about the users mailing list