IdP cookie protection
Chad La Joie
lajoie at itumi.biz
Thu Feb 23 14:29:23 GMT 2012
Yep, sorry, that's in there too
On Thu, Feb 23, 2012 at 09:26, Peter Schober <peter.schober at univie.ac.at> wrote:
> * Chad La Joie <lajoie at itumi.biz> [2012-02-23 15:22]:
>> The cookie isn't considered part of the public API so there isn't any
>> documentation of it outside the code itself. That said, the
>> protections in place are:
>> - normal cookie domain/path settings
>> - user-agent address checking
>> - cookie content signatures using a server-side, per-session secret key
>> - randomly generated sessions IDs
>
> - flagging them "secure" (might go under "normal cookies settings",
> though not domain/path related)
>
> -peter
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
--
Chad La Joie
www.itumi.biz
trusted identities, delivered
More information about the users
mailing list